Junglewise Threat Intelligence

CVE-2026-87215: Oracle Hyperion Financial Management denial of service

CVE-2026-87215 · Severity: high · CVSS 7.5 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a widely-used financial planning and consolidation system for enterprises. An unauthenticated remote attacker can cause the service to hang or crash repeatedly, rendering it unavailable to users and disrupting financial operations and reporting.

Technical details

This is a denial-of-service vulnerability in the Security component of Oracle Hyperion Financial Management. The vulnerability is easily exploitable and requires only network access via TCP; no authentication or user interaction is required. An unauthenticated attacker can send specially crafted network requests to trigger a hang or crash of the application, completely disrupting availability. The vulnerability affects version 11.2.26.0.000.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats