Junglewise Threat Intelligence

CVE-2026-87250: Oracle Hyperion Financial Management privilege escalation in Security component

CVE-2026-87250 · Severity: high · CVSS 7.6 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a critical financial planning and consolidation application used by enterprises to manage budgets and close processes. A vulnerability in its security component allows a low-privileged network user to gain unauthorized access to sensitive financial data through a social engineering attack. Successful exploitation could result in attackers viewing, modifying, or deleting confidential financial information across the system.

Technical details

This is an easily exploitable vulnerability in Oracle Hyperion Financial Management (version 11.2.26.0.000) affecting the Security component. The vulnerability has a network attack vector over HTTP and requires low privilege access plus user interaction (UI:R), indicating it likely involves social engineering or phishing to trick a legitimate user into performing an action. The scope is changed, meaning the impact extends beyond the vulnerable component itself. Successful exploitation results in high confidentiality impact (unauthorized access to critical data) and low integrity impact (unauthorized modification of some data). The CVSS 3.1 score of 7.6 reflects these impacts with no availability impact. Patch status is not specified in the advisory.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats