ZeroHour

CVE-2026-87129

niche

Unauthenticated Data Manipulation Flaw in Oracle Hyperion Data Relationship Management

CVSS 3.1
9.1 critical
EPSS
Published
()
Modified
AI analysis

Oracle Hyperion Data Relationship Management (DRM) version 11.2.26.0.000 contains a critical vulnerability in its Access and security component that allows an unauthenticated attacker with network access over HTTP to compromise the application. The flaw is rated CVSS 3.1 9.1 (critical) and is described by Oracle as easily exploitable, with no privileges or user interaction required. A successful exploit gives the attacker unauthorized ability to create, delete, or modify critical data (or all DRM-accessible data) as well as unauthorized read access to that data, impacting confidentiality and integrity, though availability is not affected. Organizations running the affected on-premises version of this enterprise master-data governance tool are exposed, particularly if its HTTP endpoints are reachable beyond an internal network. No public proof of concept is known and the flaw is not on the CISA Known Exploited Vulnerabilities catalog, so there is no evidence of active exploitation to date.

What to do: Apply the Oracle Critical Patch Update that addresses this flaw on Hyperion Data Relationship Management 11.2.26.0.000 as soon as it is available for your environment. In the interim, restrict HTTP access to DRM endpoints to trusted internal networks or VPN allow-lists and block unauthenticated access at the reverse proxy or web tier. Review DRM audit logs for unexpected unauthenticated requests or unexplained data creation, modification, or deletion activity.

Affected
Oracle Hyperion Data Relationship Management11.2.26.0.000
Estimated exposure
nichelikely hundreds to low thousands of enterprise installations worldwide, with a small internet-exposed subset — Oracle publishes no install counts, but DRM is a niche enterprise performance management master-data component typically deployed on-premises inside large-finance environments rather than internet-facing, so the exposed population is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.