Security Vulnerability in Oracle Hyperion Financial Management Product
CVE-2026-87250

7.6HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 September 2026

What is CVE-2026-87250?

A security vulnerability exists within Oracle Hyperion Financial Management, allowing low privileged attackers with network access via HTTP to compromise the system. The exploitation of this vulnerability requires human interaction from an individual other than the attacker. While focused on the Oracle Hyperion Financial Management product, successful exploitation could lead to unauthorized access and manipulation of critical data. Attackers may gain the ability to perform unauthorized updates, insertions, or deletions of accessible data, potentially impacting other connected products. The vulnerability poses serious risks to data confidentiality and integrity, highlighting the importance of implementing immediate security measures.

Affected Version(s)

Oracle Hyperion Financial Management 11.2.26.0.000

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.