Executive brief
Oracle Hyperion Data Relationship Management is a financial data management system used to organize and control access to enterprise information. A vulnerability in the access control mechanism allows authenticated users with low privileges to escalate their access over the network, potentially gaining complete control of the system and accessing or modifying sensitive financial data.
Technical details
The vulnerability is a privilege escalation flaw in the access and security component of Oracle Hyperion Data Relationship Management. It requires network access via HTTP and a low-privilege user account, but no additional user interaction. An attacker with these preconditions can exploit the weakness to achieve full system compromise, including unauthorized access to data and system manipulation. The vulnerability affects version 11.2.26.0.000 and is rated difficult to exploit.
Affected products
- Oracle Hyperion Data Relationship Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed