Junglewise Threat Intelligence

CVE-2026-87230: Oracle Hyperion Financial Management authentication bypass

CVE-2026-87230 · Severity: critical · CVSS 10 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a critical enterprise financial planning and reporting platform used by organizations to manage budgets, forecasts, and financial data. This vulnerability allows unauthenticated attackers to gain complete access to sensitive financial data and modify or delete records without any authentication or user interaction, potentially compromising financial integrity and confidentiality across the organization.

Technical details

This is an authentication bypass vulnerability in Oracle Hyperion Financial Management version 11.2.26.0.000 that is exploitable over the network via HTTP without authentication. The vulnerability has a CVSS 3.1 score of 10.0 with network attack vector, low attack complexity, and no privileges or user interaction required. An unauthenticated attacker can achieve unauthorized creation, deletion, or modification of critical data as well as complete access to all data accessible to the product. The scope is changed, indicating impacts extend beyond the vulnerable component to other Oracle Hyperion products.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats