Junglewise Threat Intelligence

CVE-2026-87220: Oracle Hyperion Financial Management DoS and data manipulation in Security component

CVE-2026-87220 · Severity: high · CVSS 7.1 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and consolidation system used by enterprises to manage accounting and budgeting processes. An unauthenticated attacker with physical access to the network segment where the system runs can crash the application or modify financial data, disrupting business operations and potentially compromising the integrity of critical financial records.

Technical details

The vulnerability exists in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. An unauthenticated attacker with access to the physical communication segment (adjacent network) can exploit this weakness to cause denial of service (application hangs or crashes) or modify (update, insert, delete) accessible financial data. The vulnerability is easily exploitable and requires no special authentication or user interaction. Patch or mitigation details are not yet available in the advisory.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats