Junglewise Threat Intelligence

CVE-2026-87146: Oracle Hyperion Data Relationship Management unauthorized access in access control

CVE-2026-87146 · Severity: high · CVSS 7.1 · Published 2026-09-15

Technologies: Oracle Hyperion Data Relationship Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Data Relationship Management is an enterprise data management tool used by organizations to manage complex financial and operational data hierarchies. A vulnerability in the access control component allows low-privileged network users to bypass authorization checks, potentially exposing sensitive business data, financial records, or allowing unauthorized modification of critical information.

Technical details

This is an access control bypass vulnerability in the Data Relationship Management (DRM) component of Oracle Hyperion, affecting version 11.2.26.0.000. The vulnerability is easily exploitable via HTTP by an authenticated low-privileged attacker with network access, requiring no user interaction. A successful exploit can result in unauthorized read access to sensitive data and unauthorized modification (insert, update, delete) of accessible DRM data. The vulnerability has a CVSS 3.1 score of 7.1, indicating high severity with significant confidentiality and integrity impacts.

Affected products

  • Oracle Hyperion Data Relationship Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats