Junglewise Threat Intelligence

CVE-2026-87135: Oracle Hyperion Data Relationship Management access control bypass

CVE-2026-87135 · Severity: high · CVSS 7.1 · Published 2026-09-15

Technologies: Oracle Hyperion Data Relationship Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Data Relationship Management is an enterprise application used to manage master data and relationships within large organizations. A network-accessible vulnerability in the access and security controls allows a low-privileged user to view sensitive business data and make unauthorized changes, potentially exposing critical financial and operational information used across the enterprise.

Technical details

The vulnerability is an access control issue in the access and security component of Oracle Hyperion Data Relationship Management. It is easily exploitable and requires low privilege credentials plus network access via HTTP, with no user interaction necessary. An authenticated attacker can achieve unauthorized read access to critical data and unauthorized write access (update, insert, delete) to some protected data. The vulnerability affects version 11.2.26.0.000, and patches are expected from Oracle as part of regular security updates.

Affected products

  • Oracle Hyperion Data Relationship Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats