Junglewise Threat Intelligence

CVE-2026-87130: Oracle Hyperion Data Relationship Management authentication bypass in SMTP

CVE-2026-87130 · Severity: high · CVSS 7.4 · Published 2026-09-15

Technologies: Oracle Hyperion Data Relationship Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Data Relationship Management is a enterprise data management system used to manage critical business data across organizations. An unauthenticated attacker can exploit a vulnerability in the SMTP interface to bypass authentication and gain unauthorized access to create, delete, or modify sensitive data, or read all accessible information stored in the system.

Technical details

This is an authentication bypass vulnerability in the Oracle Hyperion Data Relationship Management SMTP interface that allows unauthenticated network attackers to compromise the system. The vulnerability is difficult to exploit and requires specific preconditions via the SMTP protocol. Successful exploitation enables attackers to perform unauthorized data operations including creation, deletion, and modification of critical records, as well as full read access to all data within the system. The vulnerability affects version 11.2.26.0.000; patch availability information was not accessible from the advisory.

Affected products

  • Oracle Hyperion Data Relationship Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats