Junglewise Threat Intelligence

CVE-2026-87202: Oracle Hyperion Financial Management SQL injection in security component

CVE-2026-87202 · Severity: high · CVSS 8.8 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and analysis system used by enterprises to manage budgets and forecasts. This vulnerability allows a low-privileged user with network access to execute arbitrary SQL queries, potentially gaining complete control over the system including all data and operations. An attacker could read, modify, or delete sensitive financial data, disrupt operations, or compromise the integrity of financial records.

Technical details

The vulnerability is a SQL injection flaw in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. It requires network access and a low-privileged user account to exploit, with no additional user interaction needed. An authenticated attacker can submit malicious SQL via an unspecified vector to achieve complete compromise of the system, including confidentiality, integrity, and availability of data. A patch is expected from Oracle; refer to official security advisories for remediation details.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats