Junglewise Threat Intelligence

CVE-2026-87199: Oracle Hyperion Financial Management denial of service via HTTP

CVE-2026-87199 · Severity: high · CVSS 7.5 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is an enterprise financial planning and consolidation system used by organizations to manage budgets and financial reporting. An unauthenticated attacker can exploit this vulnerability over the network to crash the application repeatedly or cause it to stop responding, resulting in service outages that prevent financial staff from accessing critical planning and reporting functions.

Technical details

This is a denial-of-service vulnerability in Oracle Hyperion Financial Management's security component affecting version 11.2.26.0.000. The vulnerability is easily exploitable and requires no authentication, with the attack vector being HTTP network traffic. An unauthenticated attacker with network access can send specially crafted HTTP requests to trigger a hang or crash condition, causing a complete denial of service. The flaw impacts only availability; no confidentiality or integrity compromise is possible.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats