Executive brief
Oracle Hyperion Data Relationship Management is a financial and operational data consolidation platform used by enterprises for planning, budgeting, and reporting. A vulnerability in its access and security controls allows a high-privileged attacker with network access to bypass authentication and gain unauthorized access to sensitive financial data or modify critical records, potentially affecting downstream reporting and compliance systems.
Technical details
The vulnerability is an access control bypass in the access and security component of Oracle Hyperion Data Relationship Management. It is easily exploitable and requires a high-privileged attacker with network access via HTTP to trigger the vulnerability. Successful exploitation allows an attacker to read all accessible data in the application and perform unauthorized updates, inserts, or deletions on some data. The vulnerability exhibits scope change, meaning compromises to this component may significantly impact other Oracle Hyperion products and integrated systems.
Affected products
- Oracle Hyperion Data Relationship Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed