Junglewise Threat Intelligence

CVE-2026-87132: Oracle Hyperion Data Relationship Management CSRF in Access and security

CVE-2026-87132 · Severity: high · CVSS 7.6 · Published 2026-09-15

Technologies: Oracle Hyperion Data Relationship Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Data Relationship Management is a critical enterprise data management system used to define and maintain relationships between financial and operational data. A vulnerability in its access control mechanism allows a low-privileged attacker with network access to manipulate data and gain unauthorized access to sensitive information, particularly when a user can be socially engineered into clicking a malicious link or performing an unintended action.

Technical details

This is a cross-site request forgery (CSRF) or similar client-side manipulation vulnerability in the Access and security component of Oracle Hyperion Data Relationship Management version 11.2.26.0.000. The vulnerability requires network access (HTTP) and a low-privileged authenticated account, but exploitation depends on user interaction (social engineering or trick). The attack leverages a scope change that allows impacts beyond the directly affected product. Successful exploitation results in unauthorized read access to critical data and limited write/delete capabilities. A patch is likely available from Oracle's October 2026 Critical Patch Update (based on the published advisory date), though the referenced security alert page is currently unreachable.

Affected products

  • Oracle Hyperion Data Relationship Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats