Junglewise Threat Intelligence

CVE-2026-87246: Oracle Hyperion Financial Management authentication bypass in Security component

CVE-2026-87246 · Severity: high · CVSS 7.2 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and analysis solution used by enterprises to manage budgets and forecasts. A vulnerability in its security component allows a high-privileged attacker with network access to completely compromise the system, potentially gaining control of all financial data and operations.

Technical details

The vulnerability is an authentication or authorization bypass in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. It is easily exploitable via HTTP from a network-accessible attacker with high privileges (administrative or similar access level), requiring no user interaction. A successful exploit allows complete takeover of the application, with impacts to confidentiality, integrity, and availability. Patching information is not specified in the advisory.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats