Junglewise Threat Intelligence

CVE-2026-87187: Oracle Hyperion Financial Management authentication bypass in security component

CVE-2026-87187 · Severity: high · CVSS 8.8 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a widely-used financial planning and consolidation system for enterprise organizations. An unauthenticated attacker with physical access to the network segment containing the system can bypass security controls and gain full administrative control, threatening the confidentiality, integrity, and availability of critical financial data and operations.

Technical details

This vulnerability in the security component of Oracle Hyperion Financial Management (version 11.2.26.0.000) allows unauthenticated attackers with adjacent network access to compromise the system. The attack vector is adjacent (AV:A), requiring physical access to the communication segment, but authentication is not required (PR:N) and no user interaction is needed (UI:N). Successful exploitation results in complete system takeover (full confidentiality, integrity, and availability compromise). The vulnerability is easily exploitable with low attack complexity (AC:L). Patch availability has not been confirmed in the provided advisory text.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats