ZeroHour

CVE-2026-87130

niche

Unauthenticated SMTP Attack in Oracle Hyperion DRM 11.2.26 Risks Data Tampering

CVSS 3.1
7.4 high
EPSS
Published
()
Modified
AI analysis

Oracle Hyperion Data Relationship Management (DRM) 11.2.26.0.000 contains a flaw in its Access and Security component that allows an unauthenticated, remote attacker with network access via SMTP to compromise the product. Oracle rates the vulnerability as difficult to exploit (attack complexity: high), but successful attacks can result in unauthorized creation, deletion, or modification of critical data — or all DRM-accessible data — as well as unauthorized read access to that data (CVSS 3.1 base score 7.4, high confidentiality and integrity impact, no availability impact). Only the supported release 11.2.26.0.000 is listed as affected. Exposure is limited to enterprise on-premises performance management deployments, and the SMTP-reachable attack surface is typically internal rather than internet-facing. No public proof of concept exists, the CVE is not on CISA's KEV, and no in-the-wild exploitation has been reported.

What to do: Apply the Oracle Critical Patch Update release that remediates this CVE and upgrade off 11.2.26.0.000 as soon as the fixed version is available. Restrict SMTP and network access to the DRM server to trusted mail relays and internal subnets to shrink the unauthenticated attack surface. Review DRM audit and change logs for any unauthorized data creation, deletion, or modification, since exploitation requires no credentials and directly threatens master-data integrity.

Affected
Oracle Hyperion Data Relationship Management11.2.26.0.000
Estimated exposure
niche≈ low thousands of enterprise installations worldwide (clearly an estimate) — DRM is a per-organization licensed, on-premises EPM module used mainly by large finance organizations and normally deployed behind corporate firewalls, and no public scan or install-count data exists for it.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.