CVE-2026-87130
nicheUnauthenticated SMTP Attack in Oracle Hyperion DRM 11.2.26 Risks Data Tampering
Oracle Hyperion Data Relationship Management (DRM) 11.2.26.0.000 contains a flaw in its Access and Security component that allows an unauthenticated, remote attacker with network access via SMTP to compromise the product. Oracle rates the vulnerability as difficult to exploit (attack complexity: high), but successful attacks can result in unauthorized creation, deletion, or modification of critical data — or all DRM-accessible data — as well as unauthorized read access to that data (CVSS 3.1 base score 7.4, high confidentiality and integrity impact, no availability impact). Only the supported release 11.2.26.0.000 is listed as affected. Exposure is limited to enterprise on-premises performance management deployments, and the SMTP-reachable attack surface is typically internal rather than internet-facing. No public proof of concept exists, the CVE is not on CISA's KEV, and no in-the-wild exploitation has been reported.
What to do: Apply the Oracle Critical Patch Update release that remediates this CVE and upgrade off 11.2.26.0.000 as soon as the fixed version is available. Restrict SMTP and network access to the DRM server to trusted mail relays and internal subnets to shrink the unauthenticated attack surface. Review DRM audit and change logs for any unauthorized data creation, deletion, or modification, since exploitation requires no credentials and directly threatens master-data integrity.
| Oracle Hyperion Data Relationship Management | 11.2.26.0.000 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.