Junglewise Threat Intelligence

CVE-2026-87238: Oracle Hyperion Financial Management privilege escalation

CVE-2026-87238 · Severity: high · CVSS 8.8 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is an enterprise financial planning and reporting system used by organizations to manage budgets, forecasts, and consolidated financial data. A vulnerability in the security component allows a low-privileged user with network access to exploit the system via SQL, potentially gaining complete control over the application and its data, including unauthorized access to sensitive financial information.

Technical details

This vulnerability exists in the security component of Oracle Hyperion Financial Management version 11.2.26.0.000 and is exploitable via SQL injection or SQL-based privilege escalation. The flaw allows a low-privileged authenticated attacker with network access to bypass security controls and achieve complete system compromise. Successful exploitation results in full confidentiality, integrity, and availability impact—meaning an attacker can read, modify, and delete critical financial data or disable the system entirely. No patch availability information is currently available from the provided advisory.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats