CVE-2026-87144
nicheAuthenticated Interaction-Dependent Data Access Flaw in Oracle Hyperion DRM 11.2.26
Oracle Hyperion Data Relationship Management (DRM) 11.2.26.0.000 contains a flaw in its Access and security component that allows a low-privileged, authenticated attacker with HTTP network access to compromise the product, with successful attacks requiring human interaction from a person other than the attacker (consistent with a CSRF-style or social-engineering-assisted attack). Because the vulnerability changes scope, a successful attack can also significantly impact products beyond DRM itself. The impact is high confidentiality and low integrity: an attacker can gain unauthorized read access to critical data or all DRM-accessible data, and can also insert, update, or delete some of that data. Only DRM 11.2.26.0.000 is listed as affected. There is no evidence of public exploitation: no public PoC is known and the CVE is not on the CISA KEV list.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87144 and move off 11.2.26.0.000 per Oracle's CPU guidance. Restrict HTTP access to DRM endpoints to trusted networks and VPN users, and review logs for anomalous read or write activity by low-privilege accounts. Because exploitation requires user interaction, remind users not to open unsolicited links or approve unexpected requests while authenticated to Hyperion applications.
| Oracle Hyperion Data Relationship Management | 11.2.26.0.000 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.