Executive brief
Oracle Hyperion Data Relationship Management is an enterprise data management platform used to maintain complex data relationships and hierarchies across organizations. A vulnerability in the access and security component allows authenticated users with low privileges to escalate their permissions and take complete control of the system, potentially exposing or altering sensitive financial and operational data.
Technical details
This is a privilege escalation vulnerability in the access and security component of Oracle Hyperion Data Relationship Management. The vulnerability requires a low-privileged attacker with network access via HTTP, though exploitation is considered difficult due to complex prerequisites (AC:H). The root cause is in the access control mechanism that fails to properly validate user permissions. Successful exploitation allows an attacker to gain complete system control (takeover) with impacts to confidentiality, integrity, and availability. The affected version is 11.2.26.0.000; patch availability should be verified through Oracle's official security advisories.
Affected products
- Oracle Hyperion Data Relationship Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed