Vulnerability in Oracle Hyperion Financial Management Security Component
CVE-2026-87240

7HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 September 2026

What is CVE-2026-87240?

A vulnerability exists in the Oracle Hyperion Financial Management product that could allow a low-privileged attacker with access to the infrastructure to exploit the security component of the application. The compromise could lead to unauthorized takeover, affecting the confidentiality, integrity, and availability of critical financial data managed by Oracle Hyperion. The supported version impacted is 11.2.26.0.000, highlighting the necessity for organizations to evaluate their security posture and implement available patches to mitigate this risk.

Affected Version(s)

Oracle Hyperion Financial Management 11.2.26.0.000

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.