CVE-2026-87147
nichePrivileged Data Access Flaw in Oracle Hyperion Data Relationship Management 11.2.26
Oracle Hyperion Data Relationship Management (DRM) version 11.2.26.0.000 contains a vulnerability in its Access and security component that lets a high-privileged, authenticated attacker with network access via HTTP compromise the product, though exploitation is rated as difficult (Attack Complexity: High). A successful attack results in unauthorized creation, deletion, or modification of critical data — or all DRM-accessible data — as well as unauthorized read access to that data, with significant confidentiality and integrity impact (CVSS 3.1: 7.7). Because of a scope change, successful attacks may also significantly affect additional products beyond DRM itself, likely other components of the Oracle Hyperion/EPM stack. Affected organizations are enterprises running the supported on-premises DRM release 11.2.26.0.000, typically finance and master-data-management deployments. There is no known public proof of concept and no indication of in-the-wild exploitation (not on the CISA KEV list).
What to do: Apply the Oracle Critical Patch Update that addresses this issue as soon as it is available for DRM 11.2.26.0.000 and verify no other affected versions remain in your estate. Restrict HTTP/network access to the DRM application tier to trusted administrative sources only, and tightly review and monitor high-privileged DRM accounts, since exploitation requires existing elevated credentials. Audit DRM data hierarchies and access logs for unauthorized creations, deletions, or modifications, and assess whether other Hyperion/EPM components sharing the environment are reachable given the noted scope change.
| Oracle Hyperion Data Relationship Management | 11.2.26.0.000 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N).
- Vector
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.