Junglewise Threat Intelligence

CVE-2026-87240: Oracle Hyperion Financial Management privilege escalation in Security component

CVE-2026-87240 · Severity: high · CVSS 7 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and consolidation system used by organizations to manage budgets and accounting processes. A privilege escalation vulnerability in the security component allows a low-privileged user with local access to take full control of the application, compromising the confidentiality, integrity, and availability of financial data.

Technical details

This is a privilege escalation vulnerability in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. The vulnerability requires local access to the infrastructure where the application runs and low-level privileges, but exploitation is difficult due to high complexity (AC:H). Successful exploitation allows an attacker to achieve complete compromise of the Hyperion Financial Management system with high impact on confidentiality, integrity, and availability. No patch availability information is currently confirmed.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats