CVE-2026-87222
nicheUnauthenticated Denial-of-Service in Oracle Hyperion Financial Management 11.2.26
Oracle Hyperion Financial Management version 11.2.26.0.000 contains an easily exploitable flaw in its Security component that allows an unauthenticated attacker with network access via HTTP to hang or repeatedly crash the application, causing a complete denial of service. The vulnerability is triggered remotely with no privileges or user interaction required, and successful attacks affect only availability — confidentiality and integrity are not impacted. Organizations running the affected on-premises enterprise performance management software, typically corporate finance and consolidation systems, are at risk of having financial close and reporting workflows taken offline. The issue is rated high severity with a CVSS 3.1 base score of 7.5. It is not listed in CISA's Known Exploited Vulnerabilities catalog, no public proof-of-concept is known, and there is no evidence of in-the-wild exploitation.
What to do: Apply the Oracle Critical Patch Update that remediates this issue as soon as Oracle releases it for Hyperion 11.2.26.0.000. In the interim, restrict HTTP access to Hyperion Financial Management endpoints at the network layer so only trusted finance users and subnets can reach the service. Monitor for unexplained hangs or repeated crashes of the service and check logs for unauthenticated requests from unexpected sources.
| Oracle Hyperion Financial Management | 11.2.26.0.000 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
- Weakness
- CWE-400
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.