Executive brief
Oracle Hyperion Data Relationship Management is a data governance and management platform used by enterprises to control and organize critical business data. A vulnerability in the product's access and security controls allows privileged attackers with network access to bypass authorization checks, potentially reading, modifying, or deleting sensitive data across the system and impacting other connected Oracle Hyperion products.
Technical details
This is an access control vulnerability in the access and security component of Oracle Hyperion Data Relationship Management. The vulnerability is difficult to exploit and requires a high-privileged attacker with network access via HTTP; no user interaction is needed. A successful exploit allows the attacker to bypass authorization controls to create, delete, or modify critical data, or to read all accessible data in the system. The scope is marked as changed, meaning the impact extends beyond the vulnerable component to other Oracle Hyperion products. Patches are typically available through Oracle's standard security update channels.
Affected products
- Oracle Hyperion Data Relationship Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed