CVE-2026-87131
nicheAuthenticated Data-Access Flaw in Oracle Hyperion Data Relationship Management 11.2.26
CVE-2026-87131 is a vulnerability in the Access and Security component of Oracle Hyperion Data Relationship Management (DRM) affecting version 11.2.26.0.000. A low-privileged attacker with network access via HTTP can exploit the flaw, but successful attacks require human interaction from a person other than the attacker, such as tricking an authorized user into performing an action, and the issue may also significantly impact additional products beyond DRM (scope change). Successful exploitation can result in unauthorized access to critical data or complete access to all DRM-accessible data, as well as unauthorized update, insert, or delete access to some of that data (high confidentiality impact, low integrity impact, no availability impact). Organizations running Oracle Hyperion DRM 11.2.26.0.000 are affected. The vulnerability is not listed in CISA's KEV catalog and no public proof-of-concept is known, so exploitation in the wild is not currently indicated.
What to do: Apply Oracle's Critical Patch Update for Hyperion Data Relationship Management that addresses CVE-2026-87131 and move off version 11.2.26.0.000 as soon as the fixed release is available. In the interim, restrict network access to the DRM HTTP/web endpoints to trusted users and networks, and monitor DRM audit logs for unexpected data reads or modifications by low-privileged accounts. Because exploitation requires user interaction, remind DRM users not to act on unsolicited requests or links while using the application.
| Oracle Hyperion Data Relationship Management (Oracle Hyperion) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.