Junglewise Threat Intelligence

CVE-2026-87239: Oracle Hyperion Financial Management authentication bypass in Security component

CVE-2026-87239 · Severity: high · CVSS 7.2 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is an enterprise financial planning and consolidation platform used by organizations to manage accounting, budgeting, and reporting processes. An authentication or privilege escalation flaw in the Security component allows an attacker with high privileges to completely compromise the system via the network, potentially leading to unauthorized access to sensitive financial data and system takeover.

Technical details

An easily exploitable vulnerability exists in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. The vulnerability requires network access via HTTP and high privilege level to trigger. Successful exploitation allows an attacker to achieve complete compromise of the system, affecting confidentiality, integrity, and availability. The attack vector is network-based with no user interaction required. Patches or updates are expected from Oracle as part of their security advisory cycle; refer to official Oracle security bulletins for remediation guidance.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats