Junglewise Threat Intelligence

CVE-2026-87204: Oracle Hyperion Financial Management privilege escalation via HTTP

CVE-2026-87204 · Severity: high · CVSS 8.8 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and consolidation system used by large enterprises to manage accounting and reporting processes. A vulnerability in its security component allows an attacker with low privileges and network access to take complete control of the system, potentially compromising sensitive financial data and disrupting critical business operations.

Technical details

A low-privileged attacker with network access can exploit a vulnerability in the Oracle Hyperion Financial Management security component via HTTP to achieve complete system compromise. The vulnerability requires low privilege level but no user interaction (UI:N), and can be exploited over the network with low attack complexity. Successful exploitation results in takeover of the entire application with high impact to confidentiality, integrity, and availability. The affected version is 11.2.26.0.000; patch availability should be verified through Oracle's security advisories.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats