Executive brief
Oracle Hyperion Data Relationship Management is a critical enterprise data management system used to define and maintain relationships between financial and operational data. A vulnerability in its access control mechanism allows a low-privileged attacker with network access to manipulate data and gain unauthorized access to sensitive information, particularly when a user can be socially engineered into clicking a malicious link or performing an unintended action.
Technical details
This is a cross-site request forgery (CSRF) or similar client-side manipulation vulnerability in the Access and security component of Oracle Hyperion Data Relationship Management version 11.2.26.0.000. The vulnerability requires network access (HTTP) and a low-privileged authenticated account, but exploitation depends on user interaction (social engineering or trick). The attack leverages a scope change that allows impacts beyond the directly affected product. Successful exploitation results in unauthorized read access to critical data and limited write/delete capabilities. A patch is likely available from Oracle's October 2026 Critical Patch Update (based on the published advisory date), though the referenced security alert page is currently unreachable.
Affected products
- Oracle Hyperion Data Relationship Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed