Executive brief
Oracle Hyperion Data Relationship Management is a financial planning and analysis platform used to manage enterprise data relationships and access controls. A vulnerability in its access and security component allows a low-privileged attacker with network access to bypass authentication and gain unauthorized access to sensitive financial and operational data stored within the system, potentially affecting multiple dependent applications.
Technical details
The vulnerability is an authentication or access control bypass in the access and security component of Oracle Hyperion Data Relationship Management. It is easily exploitable by a low-privileged attacker over the network (TCP) without requiring user interaction. The vulnerability has a scope change, meaning successful exploitation can impact systems beyond the vulnerable component itself. An attacker can achieve unauthorized access to critical data or complete disclosure of all data accessible through the Hyperion DRM system. The affected version is 11.2.26.0.000; patch or mitigation guidance should be obtained from Oracle security advisories.
Affected products
- Oracle Hyperion Data Relationship Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed