Junglewise Threat Intelligence

CVE-2026-87201: Oracle Hyperion Financial Management privilege escalation in Security component

CVE-2026-87201 · Severity: high · CVSS 8.8 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and consolidation platform used by enterprises to manage corporate accounting and reporting. A low-privileged user with network access can exploit a vulnerability in the security component to gain full control of the system, compromising the confidentiality, integrity, and availability of financial data and operations.

Technical details

This vulnerability is an easily exploitable privilege escalation in Oracle Hyperion Financial Management's security component, accessible via HTTP to unauthenticated or low-privileged network users. The vulnerability allows an attacker with low privileges to bypass security controls and achieve complete system compromise. Successful exploitation results in full control of the Hyperion Financial Management instance, with impacts to confidentiality, integrity, and availability of the application and data. The vulnerability affects version 11.2.26.0.000; patch status and mitigations should be obtained from Oracle's security advisory.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats