Junglewise Threat Intelligence

CVE-2026-87145: Oracle Hyperion Data Relationship Management authentication bypass

CVE-2026-87145 · Severity: high · CVSS 7.3 · Published 2026-09-15

Technologies: Oracle Hyperion Data Relationship Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Data Relationship Management is an enterprise tool used to model and manage complex data relationships across financial systems. An unauthenticated network attacker can bypass access controls to read, modify, or delete sensitive data, and can also cause service disruptions. This could enable unauthorized access to financial data, data manipulation, and operational outages.

Technical details

This is an authentication bypass or access control vulnerability in Oracle Hyperion Data Relationship Management's HTTP interface. The vulnerability requires no user interaction and is easily exploitable via the network; no authentication credentials are needed to trigger it. An attacker can read a subset of application data (confidentiality impact), update, insert, or delete data (integrity impact), and trigger a partial denial of service condition (availability impact). The vulnerability affects version 11.2.26.0.000. Patch availability from Oracle is expected per their standard security update cycle.

Affected products

  • Oracle Hyperion Data Relationship Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats