Junglewise Threat Intelligence

CVE-2026-87194: Oracle Hyperion Financial Management unauthenticated access in Security component

CVE-2026-87194 · Severity: high · CVSS 7.5 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and close tool used by enterprises to manage budgets, forecasts, and consolidations. A vulnerability in the Security component allows unauthenticated attackers to bypass authentication over the network and gain unauthorized access to sensitive financial data, potentially exposing critical business information without requiring valid credentials.

Technical details

The vulnerability is an authentication bypass in the Security component of Oracle Hyperion Financial Management that allows unauthenticated attackers to access the application via HTTP. The flaw has a low attack complexity and requires no user interaction, making it easily exploitable. Successful exploitation grants unauthorized access to all data accessible within the Hyperion Financial Management system, with no integrity or availability impact reported. The vulnerability affects version 11.2.26.0.000, and patch information is not currently available in the advisory.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed: Published to NVD

References

Related threats