Junglewise Threat Intelligence

CVE-2026-87191: Oracle Hyperion Financial Management privilege escalation and data access

CVE-2026-87191 · Severity: high · CVSS 7.1 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a widely-used enterprise application for financial consolidation and reporting. A vulnerability in its security component allows low-privileged network users to gain unauthorized access to sensitive financial data and cause service disruptions, potentially exposing critical business information and impacting financial operations.

Technical details

A privilege escalation vulnerability exists in the security component of Oracle Hyperion Financial Management version 11.2.26.0.000. The vulnerability is easily exploitable and allows a low-privileged attacker with network access via HTTP to escalate privileges without user interaction. Successful exploitation results in unauthorized read access to all accessible financial data within the application and the ability to cause partial denial of service. Authentication is required to exploit this vulnerability (low-privileged user account needed). Oracle has assigned CVE-2026-87191 to this issue with a CVSS 3.1 score of 7.1.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats