Junglewise Threat Intelligence

CVE-2026-87190: Oracle Hyperion Financial Management authentication bypass in security component

CVE-2026-87190 · Severity: high · CVSS 7.5 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and consolidation software used by enterprises to manage complex financial operations and reporting. A vulnerability in the security component allows a low-privileged attacker with network access to bypass authentication controls and potentially take over the entire system, affecting confidentiality, integrity, and availability of critical financial data and operations.

Technical details

This is a difficult-to-exploit authentication or authorization bypass vulnerability in the security component of Oracle Hyperion Financial Management. The vulnerability requires low privilege credentials and network access via HTTP; successful exploitation allows an attacker to gain full control of the application, compromising all data and functionality. The affected version is 11.2.26.0.000. Oracle has published a security advisory addressing this issue, though detailed technical information regarding the root cause and patch status is not readily accessible from the provided reference URLs.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats