CVE-2026-87139
moderateLow-Privilege Account Takeover Risk in Oracle Hyperion Data Relationship Management
CVE-2026-87139 is a vulnerability in the Access and security component of Oracle Hyperion Data Relationship Management (DRM), affecting supported version 11.2.26.0.000. A remote attacker who already holds a low-privileged account and can reach the DRM web interface over HTTP can send specially crafted requests that, if successful, allow a complete takeover of the Data Relationship Management installation with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.5). Oracle rates the vulnerability as difficult to exploit (attack complexity: high), meaning an attacker would likely need significant effort or favorable conditions to succeed. Organizations running the affected 11.2.26.0.000 release are exposed, particularly where DRM web endpoints are reachable by broad user populations or over untrusted networks. There is no known public proof of concept, the issue is not on CISA's KEV list, and no in-the-wild exploitation has been reported; the fix is expected via Oracle's Critical Patch Update process.
What to do: Apply the Oracle Critical Patch Update that addresses this issue for Hyperion Data Relationship Management as soon as it is available. Until patched, restrict HTTP access to the DRM web tier to trusted internal networks or VPN, audit low-privileged and dormant accounts on the platform, and review logs for anomalous requests from authenticated users against Access and security endpoints.
| Oracle Hyperion Data Relationship Management | 11.2.26.0.000 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.