CVE-2026-87148
nicheUnauthenticated DoS in Oracle Hyperion Data Relationship Management 11.2.26.0.000
CVE-2026-87148 is an easily exploitable denial-of-service vulnerability in the Access and security component of Oracle Hyperion Data Relationship Management (DRM), affecting supported version 11.2.26.0.000. An unauthenticated attacker with network access via HTTP can send requests that cause the DRM service to hang or crash repeatedly, resulting in complete denial of service of the product. The flaw impacts only availability — there is no impact on confidentiality or integrity (CVSS 3.1 base score 7.5, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Organizations running the affected version, particularly those with DRM web endpoints reachable by untrusted networks, are at risk of service disruption to their enterprise data governance workflows. No public proof-of-concept is known, the issue is not on the CISA KEV list, and no exploitation in the wild has been reported.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87148 to any DRM instance running version 11.2.26.0.000. Until patched, restrict network access to the DRM HTTP endpoints (via firewall rules or VPN) so only authenticated, trusted users and networks can reach the service, since the flaw requires no credentials. Monitor DRM service logs for unexplained hangs or repeated crashes, which may indicate attempted exploitation.
| Oracle Hyperion Data Relationship Management | 11.2.26.0.000 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.