ZeroHour

CVE-2026-87140

niche

Low-Privilege Account Takeover Flaw in Oracle Hyperion Data Relationship Management 11.2.26

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87140 is a vulnerability in the Access and Security component of Oracle Hyperion Data Relationship Management (DRM) affecting version 11.2.26.0.000. A remote attacker who already holds low-privileged credentials can exploit the flaw over HTTP to fully compromise the DRM installation, with high impact on confidentiality, integrity, and availability. The vulnerability is rated difficult to exploit (Attack Complexity: High), meaning successful attacks likely require specialized conditions or repeated attempts. Organizations running the affected on-premises version of Hyperion DRM with network-accessible web interfaces and low-privilege user accounts are exposed. There is no known public proof of concept and no indication of in-the-wild exploitation; the flaw is not on the CISA Known Exploited Vulnerabilities list.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87140 as soon as it is available for your release, and check My Oracle Support for a fixed build of DRM 11.2. In the interim, restrict network access to Hyperion DRM HTTP endpoints (VPNs, allowlists, or internal-only routing), audit and minimize low-privilege accounts, and monitor logs for anomalous privileged activity originating from ordinary user sessions.

Affected
Oracle Hyperion Data Relationship Management11.2.26.0.000
Estimated exposure
nichelikely low thousands of enterprise installations worldwide (estimate; no official count) — Oracle Hyperion Data Relationship Management is on-premises enterprise performance management software deployed mainly in finance organizations of mid-to-large companies, with no public active-install counts, so exposure is estimated at…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.