Junglewise Threat Intelligence

CVE-2026-87231: Oracle Hyperion Financial Management unauthenticated remote code execution

CVE-2026-87231 · Severity: high · CVSS 8.1 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a critical financial planning and consolidation application used by enterprises to manage budgets, forecasts, and financial reporting. A vulnerability allows unauthenticated attackers on the network to gain complete control of the application, potentially exposing or modifying sensitive financial data and disrupting operations.

Technical details

The vulnerability is a difficult-to-exploit issue in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. It allows unauthenticated remote attackers with network access to compromise the system via HTTP, resulting in complete takeover (confidentiality, integrity, and availability impacts). While the root cause and exact attack mechanism are not detailed in the advisory, the combination of network accessibility, lack of authentication requirement, and full system compromise indicates a critical authentication bypass or code execution flaw. No patch information is currently available, though affected organizations should monitor Oracle's security updates.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats