Junglewise Threat Intelligence

CVE-2026-87237: Oracle Hyperion Financial Management privilege escalation in Security component

CVE-2026-87237 · Severity: high · CVSS 7.5 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a widely-used financial planning and analysis platform. A security vulnerability in its authentication or authorization logic allows a low-privilege user with network access to gain complete control over the system, compromising confidentiality, integrity, and availability of financial data and operations.

Technical details

This is a privilege escalation or authorization bypass vulnerability in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. The attack requires low-level privileges and network access via HTTP, but does not require user interaction. Successful exploitation results in complete system compromise (full confidentiality, integrity, and availability impact). The difficulty to exploit is rated as "Difficult" according to the advisory metadata, suggesting some attack complexity is required.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats