Junglewise Threat Intelligence

CVE-2026-87232: Oracle Hyperion Financial Management unauthorized data access vulnerability

CVE-2026-87232 · Severity: high · CVSS 8.1 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and consolidation application used by enterprises to manage budgets, forecasts, and accounting data. A vulnerability in the product allows an attacker with physical access to the network to read, modify, or delete sensitive financial data without authentication. This could result in unauthorized changes to critical financial records, compliance violations, and operational disruption.

Technical details

A security vulnerability in Oracle Hyperion Financial Management allows unauthenticated attackers on the same physical network segment to achieve unauthorized access to critical data. The vulnerability exists in the security component and can be exploited by an attacker with adjacent network access (AV:A). No authentication (PR:N) or user interaction (UI:N) is required. Successful exploitation permits complete read access to all accessible data and the ability to create, modify, or delete critical financial records. The advisory does not specify if a patch is available; Oracle's security alert page was inaccessible at publication time.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats