Junglewise Threat Intelligence

CVE-2026-87136: Oracle Hyperion Data Relationship Management authentication bypass in access control

CVE-2026-87136 · Severity: high · CVSS 7.5 · Published 2026-09-15

Technologies: Oracle Hyperion Data Relationship Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Data Relationship Management is an enterprise data modeling and governance platform used to manage complex data structures and access policies. An unauthenticated attacker on the network can bypass access controls via HTTP and gain unauthorized access to all sensitive data stored in the system, including critical business intelligence and customer information.

Technical details

This is an authentication bypass or access control vulnerability in the access and security component of Oracle Hyperion Data Relationship Management. The vulnerability is easily exploitable and requires only network access over HTTP; no authentication or user interaction is needed. An unauthenticated attacker can achieve complete unauthorized disclosure of all data accessible through the application, with no impact on data integrity or service availability. The affected version is 11.2.26.0.000. Oracle has released this advisory as part of their September 2026 security update.

Affected products

  • Oracle Hyperion Data Relationship Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats