Executive brief
Oracle Hyperion Data Relationship Management is a data governance and relationship platform used by enterprises to manage critical business data structures. An unauthenticated attacker can exploit a flaw in the access control layer to gain unauthorized access to sensitive data and modify or delete critical information without any credentials, potentially disrupting business operations and exposing confidential corporate data.
Technical details
The vulnerability is an authentication bypass or authorization flaw in the Access and Security component of Oracle Hyperion Data Relationship Management version 11.2.26.0.000. An unauthenticated attacker with network access can reach the affected component via HTTP without requiring authentication credentials. Successful exploitation allows the attacker to read, create, modify, or delete data accessible to the application, resulting in both confidentiality and integrity compromise of all data managed by the system. No patch information is currently available.
Affected products
- Oracle Hyperion Data Relationship Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed