Junglewise Threat Intelligence

CVE-2026-87214: Oracle Hyperion Financial Management security vulnerability in authentication

CVE-2026-87214 · Severity: critical · CVSS 9.1 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is an enterprise financial planning and consolidation platform used by organizations to manage complex financial processes. A high-severity security vulnerability in the authentication component allows privileged attackers with network access to completely compromise the system, potentially exposing or modifying sensitive financial data and disrupting critical business operations.

Technical details

This vulnerability exists in the security component of Oracle Hyperion Financial Management version 11.2.26.0.000 and can be exploited by high-privileged attackers with network access via HTTP. The vulnerability is easily exploitable (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C) and allows attackers to achieve complete system takeover. The scope is marked as changed, indicating that successful exploitation can significantly impact additional products beyond Hyperion Financial Management itself. No patch information is currently available from the provided advisory content.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats