Executive brief
Oracle Hyperion Data Relationship Management is an enterprise data governance and reporting platform used to manage financial and operational data relationships across organizations. An attacker with low-level network access can trick an authenticated user into performing unauthorized actions that grant access to sensitive financial data or allow modification of critical records, potentially compromising financial reporting and compliance systems across multiple dependent applications.
Technical details
This is a cross-site request forgery (CSRF) or privilege escalation vulnerability in the access control component of Oracle Hyperion Data Relationship Management version 11.2.26.0.000. The vulnerability requires network access via HTTP and a low-privileged attacker account, but exploitation depends on user interaction (social engineering or phishing to trick an authenticated user). Successful exploitation allows unauthorized read access to all accessible data in the product and partial write/delete access to some data. The scope is changed, meaning exploitation can impact systems beyond DRM itself. No information on patch availability is currently available.
Affected products
- Oracle Hyperion Data Relationship Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed