Junglewise Threat Intelligence

CVE-2026-87213: Oracle Hyperion Financial Management authentication bypass in HTTP

CVE-2026-87213 · Severity: high · CVSS 7.4 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is enterprise software used to manage financial planning and consolidation across large organizations. A vulnerability allows unauthenticated attackers to bypass security controls over the network, potentially exposing or modifying sensitive financial data. Successful exploitation could result in unauthorized access to or modification of critical financial records without requiring valid credentials.

Technical details

This is an authentication bypass vulnerability in the security component of Oracle Hyperion Financial Management version 11.2.26.0.000. The vulnerability is difficult to exploit and requires network access via HTTP; no user interaction or prior authentication is needed. An unauthenticated attacker can achieve unauthorized creation, deletion, or modification of critical financial data, as well as full read access to sensitive information. The vulnerability carries a CVSS 3.1 score of 7.4 with high impacts to confidentiality and integrity but no availability impact.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats