ZeroHour

CVE-2026-87128

niche

Unauthenticated Data Access Flaw in Oracle Hyperion Data Relationship Management 11.2.26

CVSS 3.1
9.1 critical
EPSS
Published
()
Modified
AI analysis

Oracle Hyperion Data Relationship Management (DRM), a component of Oracle's on-premises Enterprise Performance Management suite, contains an unauthenticated vulnerability in its Access and security component affecting supported version 11.2.26.0.000. A remote attacker with network access to the product's HTTP interface requires no credentials or user interaction to exploit the flaw, which is rated critical at CVSS 3.1 9.1. A successful attack lets the attacker create, delete, or modify critical DRM data, and read or fully access all data reachable through the product, compromising both confidentiality and integrity (availability is not impacted, indicating data compromise rather than code execution). Organizations running the affected version with the DRM web tier reachable over a network — especially any HTTP endpoint exposed to untrusted or internet-facing segments — are at risk. No public proof-of-concept exists, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and no exploitation in the wild has been reported.

What to do: Apply the Oracle Critical Patch Update covering Hyperion DRM as soon as it is released for the 11.2.26 line, and verify the applied patch level reaches the fixed build. In the interim, restrict HTTP access to DRM web endpoints so only trusted management networks or authenticated VPN users can reach them, ideally fronting the service with a reverse proxy requiring SSO. Review DRM audit logs for unauthenticated requests or unexpected data creation, modification, or deletion since the affected version was deployed.

Affected
Oracle Hyperion Data Relationship Management11.2.26.0.000
Estimated exposure
nichelikely hundreds to low thousands of installations worldwide, mostly on internal corporate networks — Oracle Hyperion DRM is an on-premises enterprise performance management product licensed mainly to large finance organizations with no public install counts; deployments are typically limited in number and not internet-facing by design,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.