CVE-2026-87133
nicheHigh-Privilege Data-Access Flaw in Oracle Hyperion Data Relationship Management
An easily exploitable flaw in the Access and Security component of Oracle Hyperion Data Relationship Management (DRM) allows a high-privileged attacker with network access via HTTP to compromise the product. Successful exploitation yields unauthorized access to critical data or complete read access to all DRM-accessible data, plus unauthorized insert, update, or delete access to some of that data, with no impact on availability. Because the vulnerability has a scope change, attacks may also significantly impact additional Oracle products beyond DRM itself. Only version 11.2.26.0.000 is listed as affected, and exploitation requires valid high-privileged credentials, so the realistic threat is from malicious insiders, compromised privileged accounts, or attackers who have already obtained such access. There is no known public proof-of-concept, no confirmed in-the-wild exploitation, and the CVE is not on the CISA Known Exploited Vulnerabilities list.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-87133 and move off the affected 11.2.26.0.000 build. Restrict HTTP access to DRM services to trusted networks or VPN, enforce least privilege and strong authentication (including MFA where possible) for privileged DRM accounts, and review audit logs for unauthorized data reads or modifications by privileged users.
| Oracle Hyperion Data Relationship Management (Oracle Hyperion) | 11.2.26.0.000 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.