Junglewise Threat Intelligence

CVE-2026-87148: Oracle Hyperion Data Relationship Management denial of service in Access and security

CVE-2026-87148 · Severity: high · CVSS 7.5 · Published 2026-09-15

Technologies: Oracle Hyperion Data Relationship Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Data Relationship Management is an enterprise data modeling and management platform used by large organizations to maintain complex data relationships. An unauthenticated attacker on the network can exploit a vulnerability in the access and security component to crash the service remotely, causing a complete denial of service with no ability to recover without manual intervention.

Technical details

This vulnerability is a network-reachable denial of service flaw in Oracle Hyperion Data Relationship Management's access and security component. The vulnerability is easily exploitable and requires no authentication or user interaction—any unauthenticated attacker with network access via HTTP can trigger it. A successful attack causes the application to hang or crash repeatedly, resulting in complete unavailability (DOS). The vulnerability affects version 11.2.26.0.000, and patch status from Oracle has not been confirmed in the provided advisory content.

Affected products

  • Oracle Hyperion Data Relationship Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats