Executive brief
Oracle Hyperion Data Relationship Management is a data governance and management system used to maintain critical business data models. An unauthenticated attacker on the network can bypass authentication via HTTP and gain unauthorized access to read, create, delete, or modify sensitive data managed by the system, compromising data integrity and confidentiality across the organization.
Technical details
The vulnerability is an authentication bypass affecting Oracle Hyperion Data Relationship Management version 11.2.26.0.000. It allows an unauthenticated attacker with network access to send HTTP requests that bypass access controls in the access and security component. No user interaction or authentication is required to exploit this vulnerability. Successful exploitation enables an attacker to perform unauthorized operations including read, create, delete, or modify access to critical or all accessible data within the system. Patch availability and specific technical root cause details are not disclosed in the advisory.
Affected products
- Oracle Hyperion Data Relationship Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed