ZeroHour

CVE-2026-87135

niche

Authenticated Privilege Escalation in Oracle Hyperion Data Relationship Management 11.2

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87135 is an easily exploitable flaw in the Access and security component of Oracle Hyperion Data Relationship Management (DRM), affecting version 11.2.26.0.000. A low-privileged (authenticated) attacker with network access to the DRM web interface over HTTP can exploit the flaw to compromise the application. A successful attack grants unauthorized read access to critical data — potentially complete access to all DRM-accessible data — as well as unauthorized update, insert, and delete access to some of that data; availability is not impacted. The vulnerability carries a CVSS 3.1 base score of 7.1 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N). Organizations running the affected on-premises DRM release are at risk, particularly where many users hold basic accounts; no public proof of concept or known in-the-wild exploitation exists at this time.

What to do: Apply Oracle's Critical Patch Update remediation for CVE-2026-87135 to any Hyperion Data Relationship Management 11.2.26.0.000 deployment as soon as it is available. Restrict HTTP access to the DRM application to trusted internal networks and authenticated users, and enforce least-privilege role assignments so low-privileged accounts cannot reach sensitive data hierarchies. Review audit logs for unexpected data reads or modifications by low-privilege accounts to rule out prior abuse.

Affected
Oracle Hyperion Data Relationship Management
Estimated exposure
nicheLikely hundreds to a few thousand enterprise installations worldwide (estimate) — Oracle Hyperion Data Relationship Management is a niche, on-premises enterprise performance management module typically deployed inside mid-to-large finance organizations, and no public install counts or internet-exposure scan data…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.