Junglewise Threat Intelligence

CVE-2026-87234: Oracle Hyperion Financial Management authorization bypass

CVE-2026-87234 · Severity: high · CVSS 8.1 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and analysis system used by enterprises to manage budgeting, forecasting, and reporting. A flaw in the security component allows a low-privilege authenticated attacker with network access to view, modify, or delete sensitive financial data without proper authorization, potentially compromising the confidentiality and integrity of critical business information.

Technical details

This is an authorization bypass vulnerability in Oracle Hyperion Financial Management (version 11.2.26.0.000) affecting the security component. The vulnerability is exploitable over HTTP and requires low privilege user credentials and network access to the application. An attacker can achieve unauthorized access to, modification of, or deletion of critical financial data within the system. No active exploitation in the wild has been reported as of the advisory date; patches are expected from Oracle.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats