Junglewise Threat Intelligence

CVE-2026-87205: Oracle Hyperion Financial Management unauthenticated data access vulnerability

CVE-2026-87205 · Severity: high · CVSS 7.5 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and reporting system used by large enterprises to manage budgets and close operations. A network-accessible vulnerability in this product allows unauthenticated attackers to access sensitive financial data and reports without authentication, potentially exposing confidential corporate financial information and competitive intelligence.

Technical details

This is an unauthenticated remote data access vulnerability in Oracle Hyperion Financial Management's security component. The vulnerability is easily exploitable over HTTP from the network without requiring prior authentication, user interaction, or elevated privileges. Successful exploitation grants attackers unauthorized access to sensitive financial data accessible through the application. The vulnerability affects version 11.2.26.0.000. Patches or mitigations should be available from Oracle; consult the security advisory for specific remediation guidance.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats