ZeroHour

CVE-2026-87138

niche

Unauthenticated Denial of Service in Oracle Hyperion Data Relationship Management

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87138 is an easily exploitable flaw in the Access and security component of Oracle Hyperion Data Relationship Management (DRM) that allows an unauthenticated attacker with network access to the product's SOAP interface to cause a complete denial of service. An attacker sends specially crafted requests over SOAP, requiring no privileges or user interaction, which can hang or repeatedly crash the DRM service, taking it offline. The impact is limited to availability — no confidentiality or integrity impact — but the affected service becomes unusable for finance and data governance teams that rely on it. Only the supported version 11.2.26.0.000 is listed as affected. There is no known public proof of concept and the vulnerability is not on the CISA Known Exploited Vulnerabilities catalog, so exploitation is not currently observed in the wild.

What to do: Apply the Oracle Critical Patch Update that addresses this CVE to all Oracle Hyperion Data Relationship Management 11.2.26.0.000 installations as soon as it is available. In the interim, restrict network access to DRM SOAP services to trusted internal subnets via firewalls or reverse-proxy allowlists, since exploitation requires network reachability to the SOAP interface. Monitor DRM service logs and process health for unexplained hangs or repeated crashes, which would indicate attempted abuse.

Affected
Oracle Hyperion Data Relationship Management
Estimated exposure
nichelikely low thousands of enterprise installations worldwide, with only a fraction internet-exposed — Oracle Hyperion DRM is an on-premises enterprise performance management component sold to a limited base of large finance organizations, and its SOAP endpoints are typically deployed on internal networks rather than exposed to the internet.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

Weakness
CWE-400
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.