Junglewise Threat Intelligence

CVE-2026-87209: Oracle Hyperion Financial Management privilege escalation in security component

CVE-2026-87209 · Severity: high · CVSS 7.1 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and consolidation application used by enterprises to manage budgets and reporting. A vulnerability in the security component allows low-privileged network users to bypass authorization controls, exposing sensitive financial data and potentially disrupting service availability.

Technical details

This is a privilege escalation vulnerability in the security component of Oracle Hyperion Financial Management affecting version 11.2.26.0.000. The vulnerability is easily exploitable via HTTP by an unauthenticated or low-privileged network attacker without requiring user interaction. Successful exploitation allows attackers to gain unauthorized access to critical financial data and execute partial denial-of-service attacks. The CVSS 3.1 score of 7.1 reflects high confidentiality impact and low availability impact.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats