Junglewise Threat Intelligence

CVE-2026-87210: Oracle Hyperion Financial Management unauthorized access in security component

CVE-2026-87210 · Severity: high · CVSS 8.3 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and consolidation system used by enterprises to manage budgets, forecasts, and accounting data. A vulnerability in its security component allows an attacker with physical access to the network segment containing the system to bypass authentication and gain unauthorized access to critical financial data, modify records, or disrupt service availability.

Technical details

This is a security bypass vulnerability in the Oracle Hyperion Financial Management security component (version 11.2.26.0.000). The vulnerability is easily exploitable and requires no authentication, but is limited to attackers with adjacent network access to the physical communication segment attached to the hardware running the product. Successful exploitation allows an attacker to create, delete, or modify critical financial data; access all stored data within the system; and partially deny service. The vulnerability affects confidentiality, integrity, and availability with a CVSS 3.1 base score of 8.3 (AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L). Patch availability and remediation details were not accessible in the provided references.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats