Executive brief
Oracle Hyperion Financial Management is an enterprise financial planning and consolidation system used by large organizations to manage budgets and close accounts. A vulnerability in the security component allows unauthenticated attackers over the network to crash the application, disrupting critical financial operations and reporting for affected users.
Technical details
This is a denial-of-service vulnerability in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. The flaw is exploitable without authentication and requires only network access via HTTP, with no special configuration or user interaction required. An attacker can send a crafted HTTP request that causes the application to hang or crash repeatedly, achieving a complete denial-of-service condition. The vulnerability is easily exploitable with low attack complexity and has high availability impact. A patch from Oracle should be consulted from their September 2026 critical patch update advisory.
Affected products
- Oracle Hyperion Financial Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed