CVE-2026-87140
nicheLow-Privilege Account Takeover Flaw in Oracle Hyperion Data Relationship Management 11.2.26
CVE-2026-87140 is a vulnerability in the Access and Security component of Oracle Hyperion Data Relationship Management (DRM) affecting version 11.2.26.0.000. A remote attacker who already holds low-privileged credentials can exploit the flaw over HTTP to fully compromise the DRM installation, with high impact on confidentiality, integrity, and availability. The vulnerability is rated difficult to exploit (Attack Complexity: High), meaning successful attacks likely require specialized conditions or repeated attempts. Organizations running the affected on-premises version of Hyperion DRM with network-accessible web interfaces and low-privilege user accounts are exposed. There is no known public proof of concept and no indication of in-the-wild exploitation; the flaw is not on the CISA Known Exploited Vulnerabilities list.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87140 as soon as it is available for your release, and check My Oracle Support for a fixed build of DRM 11.2. In the interim, restrict network access to Hyperion DRM HTTP endpoints (VPNs, allowlists, or internal-only routing), audit and minimize low-privilege accounts, and monitor logs for anomalous privileged activity originating from ordinary user sessions.
| Oracle Hyperion Data Relationship Management | 11.2.26.0.000 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.