Junglewise Threat Intelligence

CVE-2026-87247: Oracle Hyperion Financial Management security component vulnerability

CVE-2026-87247 · Severity: high · CVSS 7.5 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a widely-used enterprise financial planning and consolidation system. A security flaw in this product allows a low-privilege network attacker to take complete control of the system, potentially compromising all financial data, reports, and operations. The attack requires the attacker to already have valid credentials, but no additional user interaction is needed for exploitation.

Technical details

This is a difficult-to-exploit vulnerability in the security component of Oracle Hyperion Financial Management version 11.2.26.0.000. The attack requires low-privilege credentials and network access via HTTP; however, no user interaction is necessary. Successful exploitation grants an attacker full control over the Hyperion Financial Management system, affecting confidentiality, integrity, and availability of financial data. The CVSS 3.1 Base Score of 7.5 reflects the high impact despite the elevated exploitation difficulty. Patch status and remediation guidance should be obtained directly from Oracle security advisories.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats