Junglewise Threat Intelligence

CVE-2026-87183: Oracle Hyperion Financial Management privilege escalation in Security component

CVE-2026-87183 · Severity: high · CVSS 7.7 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and analysis tool used by enterprises to manage budgets and financial data. A vulnerability in its security component allows a high-privileged local attacker to take over the application when a user interacts with a malicious action, potentially affecting related systems and financial data integrity.

Technical details

This is an easily exploitable local privilege escalation vulnerability in Oracle Hyperion Financial Management's security component (CVE-2026-87183). The attack requires high privileges with local logon access to the infrastructure hosting the application, plus human interaction from another user. While the vulnerability is contained in Financial Management itself, successful exploitation has a scope change that may significantly impact additional connected products. Attackers can achieve complete takeover of the application, compromising confidentiality, integrity, and availability of financial data.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats