Junglewise Threat Intelligence

CVE-2026-87192: Oracle Hyperion Financial Management unauthorized access in Security component

CVE-2026-87192 · Severity: high · CVSS 7.1 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a critical enterprise financial planning and consolidation system used by organizations to manage financial data and reporting. A vulnerability in the security component allows a low-privileged network user to gain unauthorized access to sensitive financial data and cause service disruptions, potentially exposing confidential financial information and compromising business continuity.

Technical details

The vulnerability exists in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000 and is exploitable via the HTTP network interface. It requires low privilege credentials and network access, with no user interaction needed. An attacker can achieve unauthorized data access and cause partial denial of service. The vulnerability has a CVSS 3.1 score of 7.1 with impacts to confidentiality (high) and availability (low). No patch information is currently available in the advisory.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats