Junglewise Threat Intelligence

CVE-2026-87217: Oracle Hyperion Financial Management authentication bypass via HTTP

CVE-2026-87217 · Severity: critical · CVSS 9.1 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and reporting tool used by enterprises to manage budgets, forecasts, and consolidations. A vulnerability in the security component allows an attacker to connect remotely over the network without authentication and access, modify, or delete sensitive financial data, posing a critical risk to data integrity and confidentiality.

Technical details

This vulnerability in Oracle Hyperion Financial Management (version 11.2.26.0.000) is an authentication bypass affecting the security component, allowing unauthenticated remote attackers to gain unauthorized access via HTTP. The vulnerability has low attack complexity and requires no user interaction or elevated privileges, making it easily exploitable over the network. Successful exploitation allows attackers to create, modify, or delete critical data, as well as read all accessible data in the application. The vulnerability impacts both confidentiality and integrity of financial data stored in the system.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats