ZeroHour

CVE-2026-87215

niche

Unauthenticated Denial-of-Service in Oracle Hyperion Financial Management

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87215 is an easily exploitable flaw in the Security component of Oracle Hyperion Financial Management, affecting supported version 11.2.26.0.000. An unauthenticated attacker with network access via TCP can send crafted requests to trigger the flaw and cause the application to hang or crash repeatedly, resulting in a complete denial of service. The vulnerability affects only availability — there is no impact on confidentiality or integrity — and carries a CVSS 3.1 base score of 7.5. Organizations running the affected release of this on-premises enterprise financial close and consolidation platform are exposed, particularly if the service is reachable from untrusted network segments. It is not listed in the CISA Known Exploited Vulnerabilities catalog and no public proof-of-concept is known, so there is no evidence of active exploitation to date.

What to do: Apply the Oracle Critical Patch Update that remediates this issue for Hyperion Financial Management 11.2.26.0.000 as soon as it is available. Until patched, restrict TCP access to Hyperion Financial Management services to trusted internal subnets and VPN clients, and monitor for repeated crashes or hangs of the service as a sign of attempted abuse. Verify no HFM ports are unintentionally exposed to the internet via perimeter firewall rules or public scan data.

Affected
Oracle Hyperion Financial Management11.2.26.0.000
Estimated exposure
nichelow thousands of enterprise deployments worldwide, with only a small fraction internet-exposed — Hyperion Financial Management is on-premises enterprise EPM software licensed to large and mid-size finance organizations, and instances are typically deployed on internal networks rather than exposed to the internet, so the population is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

Weakness
CWE-400
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.