SQL Injection Vulnerability in Oracle Hyperion Financial Management
CVE-2026-87238
8.8HIGH
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 15 September 2026
What is CVE-2026-87238?
This vulnerability in Oracle Hyperion Financial Management exposes the application to SQL injection risks, enabling low-privileged attackers with network access to execute unauthorized SQL commands. If exploited, this could lead to a complete takeover of the application, posing significant risks to data confidentiality, integrity, and availability. Users of the affected version 11.2.26.0.000 should take immediate steps to mitigate this risk.
Affected Version(s)
Oracle Hyperion Financial Management 11.2.26.0.000