Junglewise Threat Intelligence

CVE-2026-87144: Oracle Hyperion Data Relationship Management cross-site request forgery in access control

CVE-2026-87144 · Severity: high · CVSS 7.6 · Published 2026-09-15

Technologies: Oracle Hyperion Data Relationship Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Data Relationship Management is an enterprise data governance and reporting platform used to manage financial and operational data relationships across organizations. An attacker with low-level network access can trick an authenticated user into performing unauthorized actions that grant access to sensitive financial data or allow modification of critical records, potentially compromising financial reporting and compliance systems across multiple dependent applications.

Technical details

This is a cross-site request forgery (CSRF) or privilege escalation vulnerability in the access control component of Oracle Hyperion Data Relationship Management version 11.2.26.0.000. The vulnerability requires network access via HTTP and a low-privileged attacker account, but exploitation depends on user interaction (social engineering or phishing to trick an authenticated user). Successful exploitation allows unauthorized read access to all accessible data in the product and partial write/delete access to some data. The scope is changed, meaning exploitation can impact systems beyond DRM itself. No information on patch availability is currently available.

Affected products

  • Oracle Hyperion Data Relationship Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats