ZeroHour

CVE-2026-87136

niche

Unauthenticated Data Access Flaw in Oracle Hyperion Data Relationship Management 11.2.26

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87136 is an unauthenticated information disclosure vulnerability in the Access and security component of Oracle Hyperion Data Relationship Management (DRM), affecting supported version 11.2.26.0.000. An attacker with network access via HTTP, requiring no credentials or user interaction, can exploit the flaw to gain unauthorized access to critical data or complete access to all data accessible through the DRM application. The vulnerability is rated CVSS 3.1 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), reflecting a high confidentiality impact with no direct effect on integrity or availability. Organizations running Oracle Hyperion DRM 11.2.26.0.000 — typically finance and IT teams at mid-size and large enterprises using Oracle's EPM suite — are affected. No public proof-of-concept is known, the flaw is not on the CISA KEV list, and there is no evidence of in-the-wild exploitation at this time.

What to do: Apply Oracle's Critical Patch Update for Hyperion Data Relationship Management as soon as it is available for the 11.2.26 release. Verify that no DRM 11.2.26.0.000 endpoints are reachable via HTTP from untrusted networks, and restrict access to the application with network segmentation or a reverse proxy if internet exposure is found. Review DRM access logs for unauthenticated requests to access and security endpoints that could indicate probing or attempted exploitation.

Affected
Oracle Hyperion Data Relationship Management11.2.26.0.000
Estimated exposure
nichelikely hundreds to low thousands of enterprise installations (order of magnitude ~10³) — Oracle Hyperion DRM is niche on-premises enterprise performance management software with no public install counts, deployed mainly by large finance organizations, and most instances are expected to sit on internal networks rather than…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.