ZeroHour

CVE-2026-87146

niche

Authorization Flaw in Oracle Hyperion Data Relationship Management 11.2.26

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87146 is a vulnerability in the Access and security component of Oracle Hyperion Data Relationship Management (DRM), affecting supported version 11.2.26.0.000. A low-privileged (authenticated) attacker with network access via HTTP can exploit it easily to compromise the DRM application. A successful attack can result in unauthorized read access to critical data — up to complete access to all DRM-accessible data — as well as unauthorized update, insert, or delete access to some of that data. Organizations running Oracle Hyperion DRM 11.2.26.0.000, typically large enterprises using it for financial hierarchy and master data management, are affected. There is no known public proof of concept and no evidence of in-the-wild exploitation; the flaw is not on the CISA Known Exploited Vulnerabilities catalog.

What to do: Apply the Oracle Critical Patch Update that remediates this issue for Hyperion DRM 11.2.x as soon as it is available in your patch cycle. In the meantime, restrict HTTP/network access to DRM web endpoints to trusted VPN or internal networks and review DRM audit logs for unusual data reads or modifications by low-privilege accounts. Enforce least-privilege role assignments so compromised low-tier accounts have minimal reach.

Affected
Oracle Hyperion Data Relationship Management
Estimated exposure
nichelikely low thousands of enterprise installations (order of magnitude: ~1,000s) — Oracle Hyperion DRM is on-premises enterprise performance management software deployed mainly by large finance organizations, so the install base is far smaller than mass-market software and no public install or exposure counts are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.