Junglewise Threat Intelligence

CVE-2026-87143: Oracle Hyperion Data Relationship Management unauthorized access in Access and security

CVE-2026-87143 · Severity: high · CVSS 7.4 · Published 2026-09-15

Technologies: Oracle Hyperion Data Relationship Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Data Relationship Management is a financial planning and data integration platform used by enterprises to consolidate and manage critical business data. An unauthenticated network attacker can exploit a difficult-to-exploit vulnerability in the Access and security component to gain unauthorized access to, create, delete, or modify sensitive financial and operational data, potentially compromising data integrity and exposing confidential information.

Technical details

The vulnerability exists in the Access and security component of Oracle Hyperion Data Relationship Management version 11.2.26.0.000. It allows an unauthenticated attacker with network access via TCP to bypass access controls and read, modify, or delete critical data. The vulnerability is difficult to exploit and does not require user interaction. A successful attack results in high-impact disclosure and modification of sensitive data without authentication being required. Oracle has not yet published detailed patch information; affected organizations should monitor Oracle's security advisories for remediation guidance.

Affected products

  • Oracle Hyperion Data Relationship Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats