Junglewise Threat Intelligence

CVE-2026-87211: Oracle Hyperion Financial Management authentication bypass in Security component

CVE-2026-87211 · Severity: high · CVSS 7.5 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a widely-used financial planning and consolidation system used by enterprises to manage budgeting, forecasting, and financial reporting across organizations. An unauthenticated attacker with network access can bypass security controls to gain unauthorized access to sensitive financial data, potentially exposing confidential business information, customer data, and competitive intelligence without requiring valid credentials or user interaction.

Technical details

This vulnerability exists in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000 and is exploitable over the network via HTTP. The flaw allows unauthenticated attackers to bypass authentication mechanisms and gain unauthorized access to critical data within the application. The attack requires no special privileges, user interaction, or complex configuration, making it easily exploitable. Successful exploitation results in confidentiality impact, enabling attackers to read and extract sensitive financial data accessible through the application. Patches or mitigations should be available from Oracle through their security advisory channels.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats