Junglewise Threat Intelligence

CVE-2026-87137: Oracle Hyperion Data Relationship Management cross-site request forgery in access controls

CVE-2026-87137 · Severity: high · CVSS 7.6 · Published 2026-09-15

Technologies: Oracle Hyperion Data Relationship Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Data Relationship Management is a data governance and integration tool used to manage enterprise data relationships and hierarchies. This vulnerability allows a low-privileged attacker to trick a user into performing unauthorized actions, potentially exposing or modifying critical business data across the product and related systems. The flaw requires user interaction and network access but can result in full data compromise.

Technical details

A cross-site request forgery (CSRF) or social engineering vulnerability exists in the access and security controls of Oracle Hyperion Data Relationship Management versions up to 11.2.26.0.000. The vulnerability is exploitable over HTTP by a low-privileged authenticated attacker and requires user interaction from an administrator or higher-privileged account. Successful exploitation can lead to unauthorized read access to all accessible data and partial write/delete access, with potential scope change affecting dependent products. The CVSS 3.1 score of 7.6 reflects high confidentiality and limited integrity impact. No patch availability information is currently confirmed in this advisory.

Affected products

  • Oracle Hyperion Data Relationship Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats