Executive brief
Oracle Hyperion Data Relationship Management is an enterprise data management platform used to store and manage critical business information. An attacker with low-level network access can exploit a weakness in access controls to view, modify, or delete sensitive data without authorization, requiring a legitimate user to interact with a malicious link or content. The vulnerability can impact confidentiality and integrity of data stored in the system.
Technical details
This is an access control vulnerability in the Oracle Hyperion Data Relationship Management component (version 11.2.26.0.000). The vulnerability is exploitable via HTTP by a low-privileged attacker with network access and requires user interaction (reflected attack with UI redirection). The attack has changed scope (CVSS:S:C), indicating the vulnerability can impact systems beyond the affected product. Successful exploitation allows unauthorized access to critical data and modification/deletion of accessible data. A patch is expected in Oracle's September 2026 security update.
Affected products
- Oracle Hyperion Data Relationship Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed