CVE-2026-87141
nicheBroken Access Control Exposes Critical Data in Oracle Hyperion DRM 11.2.26
CVE-2026-87141 is a vulnerability in the Access and Security component of Oracle Hyperion Data Relationship Management (DRM), affecting supported version 11.2.26.0.000. It is easily exploitable by a low-privileged, authenticated attacker who has network access to the product's HTTP interface. A successful attack results in unauthorized access to critical data or complete access to all Oracle Hyperion DRM accessible data, and due to a scope change, successful attacks may also significantly impact additional products beyond DRM itself. The issue is rated High severity with a CVSS 3.1 base score of 7.7, driven entirely by high confidentiality impact (no integrity or availability impact). No public proof-of-concept exists, the flaw is not on the CISA KEV list, and there is no indication of in-the-wild exploitation at this time.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-87141 to all Oracle Hyperion Data Relationship Management 11.2.26.0.000 installations. Restrict HTTP network access to DRM to trusted internal users and segments, and review account privileges to confirm low-privilege accounts are limited. Audit logs for anomalous data access by low-privileged accounts, since exploitation would surface as unauthorized reads of sensitive data rather than system disruption.
| Oracle Hyperion Data Relationship Management (component: Access and security) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.