Executive brief
Oracle Hyperion Data Relationship Management is a business intelligence tool used to manage and analyze financial and operational data. An unauthenticated attacker can exploit this vulnerability over the network to gain unauthorized access to sensitive data without requiring login credentials, potentially exposing critical business information to unauthorized parties.
Technical details
This is an authentication bypass or authorization vulnerability in the Access and security component of Oracle Hyperion Data Relationship Management version 11.2.25.0.000. The vulnerability is easily exploitable over HTTP and requires no authentication, user interaction, or special network positioning—only network-level access to the affected service. Successful exploitation allows an unauthenticated attacker to read and access all data managed within the application, compromising confidentiality. Oracle has released a patch; users should apply the August 2026 security update immediately.
Affected products
- Oracle Hyperion Data Relationship Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed