Junglewise Threat Intelligence

CVE-2026-87245: Oracle Hyperion Financial Management privilege escalation in Security component

CVE-2026-87245 · Severity: high · CVSS 8 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a widely-used enterprise application for budgeting, planning, and financial consolidation. A security vulnerability in version 11.2.26.0.000 allows a low-privileged attacker with local network access to the system to fully compromise the application and gain complete control over its data and operations. This could result in unauthorized access to sensitive financial data, data manipulation, or service disruption.

Technical details

This is an easily exploitable vulnerability in the Security component of Oracle Hyperion Financial Management that requires an attacker to be present on the same physical communication segment (adjacent network) and possess low-level privileges. The vulnerability allows unauthenticated or low-privileged network-based exploitation without additional user interaction or complex configuration. Successful exploitation grants complete compromise of the application with high impact to confidentiality, integrity, and availability of financial data and operations. Patches are expected from Oracle in their September 2026 security update, though complete fix details remain unclear due to Oracle's advisory access restrictions.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats