Executive brief
Oracle Hyperion Data Relationship Management is a financial planning and data integration platform used by enterprises to consolidate and manage critical business data. An unauthenticated network attacker can exploit a difficult-to-exploit vulnerability in the Access and security component to gain unauthorized access to, create, delete, or modify sensitive financial and operational data, potentially compromising data integrity and exposing confidential information.
Technical details
The vulnerability exists in the Access and security component of Oracle Hyperion Data Relationship Management version 11.2.26.0.000. It allows an unauthenticated attacker with network access via TCP to bypass access controls and read, modify, or delete critical data. The vulnerability is difficult to exploit and does not require user interaction. A successful attack results in high-impact disclosure and modification of sensitive data without authentication being required. Oracle has not yet published detailed patch information; affected organizations should monitor Oracle's security advisories for remediation guidance.
Affected products
- Oracle Hyperion Data Relationship Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed