Executive brief
Oracle Hyperion Data Relationship Management is an enterprise data modeling and governance platform used to manage complex data structures and access policies. An unauthenticated attacker on the network can bypass access controls via HTTP and gain unauthorized access to all sensitive data stored in the system, including critical business intelligence and customer information.
Technical details
This is an authentication bypass or access control vulnerability in the access and security component of Oracle Hyperion Data Relationship Management. The vulnerability is easily exploitable and requires only network access over HTTP; no authentication or user interaction is needed. An unauthenticated attacker can achieve complete unauthorized disclosure of all data accessible through the application, with no impact on data integrity or service availability. The affected version is 11.2.26.0.000. Oracle has released this advisory as part of their September 2026 security update.
Affected products
- Oracle Hyperion Data Relationship Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed