Junglewise Threat Intelligence

CVE-2026-87241: Oracle Hyperion Financial Management physical authentication bypass

CVE-2026-87241 · Severity: high · CVSS 8.1 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial consolidation and close solution used by enterprises to manage accounting and reporting data. A vulnerability allows an attacker with physical access to the network segment containing the application to bypass authentication and read, modify, or delete critical financial data without any user interaction required.

Technical details

This is an authentication bypass vulnerability in Oracle Hyperion Financial Management 11.2.26.0.000 that requires physical access to the network communication segment (adjacent network). The vulnerability allows an unauthenticated attacker to compromise the application and gain unauthorized access to create, delete, or modify critical data, as well as read sensitive financial information. The attack has no privilege requirements and does not require user interaction. Patches are expected from Oracle in their September 2026 security update.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: advisory: Oracle Security Alert published

References

Related threats