Junglewise Threat Intelligence

CVE-2026-87186: Oracle Hyperion Financial Management security vulnerability

CVE-2026-87186 · Severity: critical · CVSS 9.6 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and consolidation system used by enterprises to manage budgets, forecasts, and reporting. A critical vulnerability in its security component allows an attacker with physical access to the network segment to completely compromise the system without authentication, potentially gaining unauthorized access to sensitive financial data and disrupting operations. The impact extends beyond the affected application to potentially compromise other systems within the environment.

Technical details

This vulnerability exists in the security component of Oracle Hyperion Financial Management version 11.2.26.0.000 and is easily exploitable without requiring authentication or user interaction. The attack vector is adjacent network access, requiring the attacker to be on the same physical communication segment (e.g., local network) as the hardware running the application. A successful exploit results in complete compromise of Oracle Hyperion Financial Management with high impact to confidentiality, integrity, and availability. The vulnerability also has a scope change impact, meaning attacks on this component can significantly affect other products in the environment. Patch availability should be verified through Oracle's security advisories.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats