Junglewise Threat Intelligence

CVE-2026-87219: Oracle Hyperion Financial Management privilege escalation in Security component

CVE-2026-87219 · Severity: high · CVSS 8.4 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and consolidation platform used by enterprises to manage budgets, forecasts, and accounting data. A vulnerability in the Security component allows low-privileged users with local access to the infrastructure to gain unauthorized access to or modify critical financial data, potentially impacting the integrity and confidentiality of sensitive information across the organization.

Technical details

The vulnerability is a local privilege escalation in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. It requires low privilege logon access to the infrastructure where the product executes, with no user interaction needed. Successful exploitation allows an attacker to create, delete, or modify critical data or gain complete access to all accessible data within the application. The scope change indicates that attacks may affect additional Oracle products beyond Hyperion Financial Management itself. No patch availability is confirmed in the provided advisory.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats