ZeroHour

CVE-2026-87133

niche

High-Privilege Data-Access Flaw in Oracle Hyperion Data Relationship Management

CVSS 3.1
7.6 high
EPSS
Published
()
Modified
AI analysis

An easily exploitable flaw in the Access and Security component of Oracle Hyperion Data Relationship Management (DRM) allows a high-privileged attacker with network access via HTTP to compromise the product. Successful exploitation yields unauthorized access to critical data or complete read access to all DRM-accessible data, plus unauthorized insert, update, or delete access to some of that data, with no impact on availability. Because the vulnerability has a scope change, attacks may also significantly impact additional Oracle products beyond DRM itself. Only version 11.2.26.0.000 is listed as affected, and exploitation requires valid high-privileged credentials, so the realistic threat is from malicious insiders, compromised privileged accounts, or attackers who have already obtained such access. There is no known public proof-of-concept, no confirmed in-the-wild exploitation, and the CVE is not on the CISA Known Exploited Vulnerabilities list.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-87133 and move off the affected 11.2.26.0.000 build. Restrict HTTP access to DRM services to trusted networks or VPN, enforce least privilege and strong authentication (including MFA where possible) for privileged DRM accounts, and review audit logs for unauthorized data reads or modifications by privileged users.

Affected
Oracle Hyperion Data Relationship Management (Oracle Hyperion)11.2.26.0.000
Estimated exposure
nicheLikely low thousands of enterprise deployments at most (exact count unknown) — Oracle Hyperion DRM is licensed, largely on-premises enterprise performance management software used mainly in finance/master-data functions of mid-to-large organizations, with no public install counts or reliable internet-exposure scan…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.