Junglewise Threat Intelligence

CVE-2026-87244: Oracle Hyperion Financial Management authentication bypass in Security component

CVE-2026-87244 · Severity: high · CVSS 7.2 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and analysis platform used by enterprises to consolidate and manage accounting data. A vulnerability in the product's security component allows an authenticated administrator with network access to completely take over the system, potentially exposing or manipulating sensitive financial records and disrupting critical business operations.

Technical details

This vulnerability in Oracle Hyperion Financial Management's security component is exploitable over HTTP by a high-privileged attacker with network access and requires no additional user interaction. The vulnerability allows an attacker with administrative credentials to compromise the entire system, resulting in complete loss of confidentiality, integrity, and availability. The affected version is 11.2.26.0.000. Oracle has assigned CVSS 3.1 score 7.2 to this vulnerability, and no public exploitation in the wild has been reported at time of disclosure.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats