Junglewise Threat Intelligence

CVE-2026-87138: Oracle Hyperion Data Relationship Management denial of service via SOAP

CVE-2026-87138 · Severity: high · CVSS 7.5 · Published 2026-09-15

Technologies: Oracle Hyperion Data Relationship Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Data Relationship Management is an enterprise data management system used by organizations to maintain complex data relationships and hierarchies. An unauthenticated attacker can remotely crash or hang the application through a specially crafted SOAP message, causing complete service outage and disrupting business operations that depend on the system's availability.

Technical details

This is an unauthenticated denial-of-service vulnerability in the SOAP interface of Oracle Hyperion Data Relationship Management 11.2.26.0.000. The vulnerability can be exploited by an unauthenticated attacker with network access to the SOAP endpoint, allowing them to trigger a hang or crash of the application. The attack has a low complexity and requires no user interaction or privileges. Successful exploitation results in complete availability impact through denial of service. A patch is expected to be available through Oracle's standard security update channels.

Affected products

  • Oracle Hyperion Data Relationship Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats