Junglewise Threat Intelligence

CVE-2026-87242: Oracle Hyperion Financial Management unauthorized data access via TLS

CVE-2026-87242 · Severity: high · CVSS 7.4 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and consolidation system used by enterprises to manage accounting and budgeting operations. An unauthenticated attacker on the network can exploit a security vulnerability to read, modify, or delete sensitive financial data without authorization, compromising both the confidentiality and integrity of an organization's critical financial records.

Technical details

This is a difficult-to-exploit vulnerability in Oracle Hyperion Financial Management's security component that allows unauthenticated network attackers to compromise the system via TLS. The vulnerability enables unauthorized creation, deletion, and modification of critical data, as well as complete unauthorized access to all accessible data within the product. The attack requires network access but does not require user interaction or authentication. A patch is expected to be available through Oracle's normal security update process; refer to official Oracle security advisories for patching guidance.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats