ZeroHour

CVE-2026-87139

moderate

Low-Privilege Account Takeover Risk in Oracle Hyperion Data Relationship Management

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87139 is a vulnerability in the Access and security component of Oracle Hyperion Data Relationship Management (DRM), affecting supported version 11.2.26.0.000. A remote attacker who already holds a low-privileged account and can reach the DRM web interface over HTTP can send specially crafted requests that, if successful, allow a complete takeover of the Data Relationship Management installation with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.5). Oracle rates the vulnerability as difficult to exploit (attack complexity: high), meaning an attacker would likely need significant effort or favorable conditions to succeed. Organizations running the affected 11.2.26.0.000 release are exposed, particularly where DRM web endpoints are reachable by broad user populations or over untrusted networks. There is no known public proof of concept, the issue is not on CISA's KEV list, and no in-the-wild exploitation has been reported; the fix is expected via Oracle's Critical Patch Update process.

What to do: Apply the Oracle Critical Patch Update that addresses this issue for Hyperion Data Relationship Management as soon as it is available. Until patched, restrict HTTP access to the DRM web tier to trusted internal networks or VPN, audit low-privileged and dormant accounts on the platform, and review logs for anomalous requests from authenticated users against Access and security endpoints.

Affected
Oracle Hyperion Data Relationship Management11.2.26.0.000
Estimated exposure
moderate≈ low thousands of enterprise installations (order of magnitude: thousands), with tens of thousands of internal users — Oracle Hyperion/EPM is on-premises enterprise financial software deployed at mid-to-large organizations in the low thousands globally, with DRM a specialized subset module that is typically internal-facing rather than internet-exposed.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.