Junglewise Threat Intelligence

CVE-2026-87141: Oracle Hyperion Data Relationship Management unauthorized data access

CVE-2026-87141 · Severity: high · CVSS 7.7 · Published 2026-09-15

Technologies: Oracle Hyperion Data Relationship Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Data Relationship Management is an enterprise data management tool used to manage complex data relationships and access controls across organizations. This vulnerability allows attackers with low-level network access to bypass access controls and gain unauthorized read access to sensitive data, potentially compromising critical business information across multiple connected systems.

Technical details

This is an access control bypass vulnerability in Oracle Hyperion Data Relationship Management affecting version 11.2.26.0.000. The vulnerability resides in the Access and Security component and is exploitable via HTTP by a low-privileged attacker with network access. No user interaction or special configuration is required. Successful exploitation results in confidentiality impact with scope change, meaning the attack can affect systems beyond the primary vulnerable component. The vulnerability has a CVSS 3.1 score of 7.7 reflecting high confidentiality impact.

Affected products

  • Oracle Hyperion Data Relationship Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats