Junglewise Threat Intelligence

CVE-2026-87197: Oracle Hyperion Financial Management authentication bypass

CVE-2026-87197 · Severity: high · CVSS 8.2 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and analysis platform used by large organizations to manage budgets, forecasts, and financial data. An unauthenticated attacker can bypass security controls via a network-based exploit, gaining unauthorized access to sensitive financial data and the ability to modify or delete records without permission.

Technical details

This is an authentication bypass vulnerability in the Security component of Oracle Hyperion Financial Management. The flaw allows an unauthenticated attacker with network access to exploit the application via HTTP without requiring credentials or user interaction. Successful exploitation results in unauthorized read access to confidential financial data and the ability to perform unauthorized create, update, and delete operations on some accessible data. The vulnerability affects version 11.2.26.0.000 and has a CVSS 3.1 score of 8.2, indicating high severity. Oracle released a patch as part of their September 2026 security advisory.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: patched: Patch released as part of Oracle's September 2026 CPU

References

Related threats