Junglewise Threat Intelligence

CVE-2026-87129: Oracle Hyperion Data Relationship Management authentication bypass

CVE-2026-87129 · Severity: critical · CVSS 9.1 · Published 2026-09-15

Technologies: Oracle Hyperion Data Relationship Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Data Relationship Management is a data governance and relationship platform used by enterprises to manage critical business data structures. An unauthenticated attacker can exploit a flaw in the access control layer to gain unauthorized access to sensitive data and modify or delete critical information without any credentials, potentially disrupting business operations and exposing confidential corporate data.

Technical details

The vulnerability is an authentication bypass or authorization flaw in the Access and Security component of Oracle Hyperion Data Relationship Management version 11.2.26.0.000. An unauthenticated attacker with network access can reach the affected component via HTTP without requiring authentication credentials. Successful exploitation allows the attacker to read, create, modify, or delete data accessible to the application, resulting in both confidentiality and integrity compromise of all data managed by the system. No patch information is currently available.

Affected products

  • Oracle Hyperion Data Relationship Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats