ZeroHour

CVE-2026-87134

niche

Authenticated data disclosure flaw in Oracle Hyperion Data Relationship Management 11.2

CVSS 3.1
7.7 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87134 is an access-control vulnerability in the Access and security component of Oracle Hyperion Data Relationship Management (DRM), affecting supported version 11.2.26.0.000. A low-privileged attacker with network access to the DRM service over TCP can easily exploit the flaw to gain unauthorized access to critical data, potentially exposing all data accessible through the DRM installation. The CVSS 3.1 base score is 7.7 (high) with a scope change, meaning successful attacks can also significantly impact additional Oracle Hyperion products beyond DRM itself; only confidentiality is impacted (no integrity or availability impact). Organizations running the affected version of this on-premises enterprise performance management component are at risk of broad sensitive financial/hierarchy data exposure. There is no known public proof of concept and the flaw is not on the CISA KEV catalog, so exploitation status is none known.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87134 to your Hyperion Data Relationship Management 11.2.26.0.000 environment as soon as it is available. Restrict TCP network access to DRM services to trusted users and subnets via firewall rules, and review and minimize low-privileged DRM accounts that could be leveraged. Audit DRM access logs for unusual bulk data reads or access outside expected roles to detect any attempted abuse.

Affected
Oracle Hyperion Data Relationship Management11.2.26.0.000
Estimated exposure
nichelikely low thousands of installations at most (hundreds to ~2,000 enterprise deployments) — Oracle Hyperion DRM is a niche, separately licensed EPM component used mainly by large finance organizations in on-premises or private-cloud deployments that are typically internal-facing rather than internet-exposed, so the reachable…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.