ZeroHour

CVE-2026-87141

niche

Broken Access Control Exposes Critical Data in Oracle Hyperion DRM 11.2.26

CVSS 3.1
7.7 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87141 is a vulnerability in the Access and Security component of Oracle Hyperion Data Relationship Management (DRM), affecting supported version 11.2.26.0.000. It is easily exploitable by a low-privileged, authenticated attacker who has network access to the product's HTTP interface. A successful attack results in unauthorized access to critical data or complete access to all Oracle Hyperion DRM accessible data, and due to a scope change, successful attacks may also significantly impact additional products beyond DRM itself. The issue is rated High severity with a CVSS 3.1 base score of 7.7, driven entirely by high confidentiality impact (no integrity or availability impact). No public proof-of-concept exists, the flaw is not on the CISA KEV list, and there is no indication of in-the-wild exploitation at this time.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-87141 to all Oracle Hyperion Data Relationship Management 11.2.26.0.000 installations. Restrict HTTP network access to DRM to trusted internal users and segments, and review account privileges to confirm low-privilege accounts are limited. Audit logs for anomalous data access by low-privileged accounts, since exploitation would surface as unauthorized reads of sensitive data rather than system disruption.

Affected
Oracle Hyperion Data Relationship Management (component: Access and security)
Estimated exposure
nichelikely low thousands of installations worldwide (order of magnitude: thousands of organizations) — Oracle Hyperion DRM is a licensed enterprise performance management product deployed mainly at large organizations for internal finance/master data workflows, so the install base is small and these systems are typically not…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.