Security Vulnerability in Oracle Hyperion Financial Management by Oracle
CVE-2026-87236

7.1HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 September 2026

What is CVE-2026-87236?

A security vulnerability has been identified in the Oracle Hyperion Financial Management product, which affects version 11.2.26.0.000. This issue allows attackers with low privileges and network access via HTTP to compromise the system, potentially leading to unauthorized access to sensitive information and data stored within Oracle Hyperion Financial Management. Additionally, successful exploitation of this vulnerability could enable an attacker to partially disrupt services, resulting in a denial of service for users. Organizations using this software are urged to take immediate action to mitigate these risks.

Affected Version(s)

Oracle Hyperion Financial Management 11.2.26.0.000

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.