CVE-2026-87136
nicheUnauthenticated Data Access Flaw in Oracle Hyperion Data Relationship Management 11.2.26
CVE-2026-87136 is an unauthenticated information disclosure vulnerability in the Access and security component of Oracle Hyperion Data Relationship Management (DRM), affecting supported version 11.2.26.0.000. An attacker with network access via HTTP, requiring no credentials or user interaction, can exploit the flaw to gain unauthorized access to critical data or complete access to all data accessible through the DRM application. The vulnerability is rated CVSS 3.1 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), reflecting a high confidentiality impact with no direct effect on integrity or availability. Organizations running Oracle Hyperion DRM 11.2.26.0.000 — typically finance and IT teams at mid-size and large enterprises using Oracle's EPM suite — are affected. No public proof-of-concept is known, the flaw is not on the CISA KEV list, and there is no evidence of in-the-wild exploitation at this time.
What to do: Apply Oracle's Critical Patch Update for Hyperion Data Relationship Management as soon as it is available for the 11.2.26 release. Verify that no DRM 11.2.26.0.000 endpoints are reachable via HTTP from untrusted networks, and restrict access to the application with network segmentation or a reverse proxy if internet exposure is found. Review DRM access logs for unauthenticated requests to access and security endpoints that could indicate probing or attempted exploitation.
| Oracle Hyperion Data Relationship Management | 11.2.26.0.000 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.