Junglewise Threat Intelligence

CVE-2026-87208: Oracle Hyperion Financial Management privilege escalation in Security component

CVE-2026-87208 · Severity: high · CVSS 7.1 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and consolidation platform used by enterprises to manage budgets, forecasts, and close processes. This vulnerability allows a low-privileged network user to gain unauthorized access to sensitive financial data and modify records, potentially compromising the integrity of financial reporting and exposing confidential business information.

Technical details

This is a privilege escalation vulnerability in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. The vulnerability is easily exploitable and requires only low-privilege credentials and network access via HTTP; no user interaction is needed. Successful exploitation allows an attacker to read sensitive financial data and perform unauthorized create, update, or delete operations on database records accessible through the application. A patch or update is expected from Oracle's security advisory program.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats