Junglewise Threat Intelligence

CVE-2026-87196: Oracle Hyperion Financial Management authentication bypass

CVE-2026-87196 · Severity: high · CVSS 8.2 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial consolidation and planning application used by enterprises to manage complex financial data and reporting. This vulnerability allows an unauthenticated attacker to access the system over the network and view, modify, or delete sensitive financial data without proper credentials, potentially exposing critical business information and enabling unauthorized financial transactions.

Technical details

This is an authentication bypass vulnerability in Oracle Hyperion Financial Management version 11.2.26.0.000 that allows unauthenticated network access via HTTP. The vulnerability resides in the security component and permits an attacker to gain unauthorized access to critical data and modify or delete financial records. The attack requires only network access with no authentication or user interaction, making it easily exploitable. Confidentiality and integrity impacts are confirmed, though availability is not affected.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats