Junglewise Threat Intelligence

CVE-2026-87206: Oracle Hyperion Financial Management authentication bypass in Security component

CVE-2026-87206 · Severity: high · CVSS 7.4 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and consolidation system used by enterprises to manage accounting data and reporting. An unauthenticated attacker on the network can exploit a difficult-to-exploit vulnerability in the security component to bypass authentication and gain unauthorized access to create, modify, or delete critical financial data, potentially exposing sensitive accounting records or enabling fraudulent transactions.

Technical details

This is an authentication bypass vulnerability in Oracle Hyperion Financial Management's security component, affecting version 11.2.26.0.000. The vulnerability is remotely exploitable over HTTP without credentials, though it is marked as "difficult to exploit" with high complexity (AC:H). Successful exploitation allows an unauthenticated network-based attacker to achieve both confidentiality and integrity impacts, enabling unauthorized access to all accessible data and creation, deletion, or modification of critical financial records. No patch information is currently available in the advisory; affected organizations should monitor Oracle's security bulletins for remediation guidance.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats