Description
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-09-15
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access & Modification
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises in the Access and Security component of Oracle Hyperion Data Relationship Management and permits an unauthenticated attacker with network access via HTTP to perform unauthorized creation, deletion, or modification of data, and to gain access to all data stored in the system. This results in severe confidentiality and integrity compromise, as the attacker can read or alter critical information. The weakness is due to missing or improper authentication checks, mapping to CWE-287 and CWE-306.

Affected Systems

Oracle Corporation’s Hyperion Data Relationship Management, version 11.2.26.0.000, is affected. No other versions or products are listed as impacted. The vulnerability is specific to the Access and Security component deployed by the vendor.

Risk and Exploitability

The CVSS 3.1 base score is 9.1, indicating high magnitude with significant confidentiality and integrity impact. The EPSS score is below 1%, suggesting current observed exploitation activity is very low, but the description explicitly labels it as easily exploitable. It is not listed in CISA’s KEV catalog. The likely attack vector involves an unauthenticated HTTP request sent by an adversary over the network, requiring no privileged access or authentication. The attacker can fully control the affected instance until mitigation steps are applied.

Generated by OpenCVE AI on September 18, 2026 at 14:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest security patch or upgrade Oracle Hyperion Data Relationship Management to a version that eliminates the Access and Security flaw.
  • Restrict HTTP access to the Hyperion instance by configuring firewalls or reverse proxies to allow traffic only from trusted IP ranges.
  • Enable multi-factor authentication and enforce strong password policies to prevent unauthenticated access to the management interface.
  • Enable comprehensive logging and audit trails for data modification operations, and regularly review logs for abnormal activity.

Generated by OpenCVE AI on September 18, 2026 at 14:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Unauthorized Data Modification in Oracle Hyperion

Thu, 17 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Unauthorized Data Modification in Oracle Hyperion

Tue, 15 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
CWE-306

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle hyperion Data Relationship Management
CPEs cpe:2.3:a:oracle:hyperion_data_relationship_management:11.2.26.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Data Relationship Management
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Hyperion Data Relationship Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T22:54:41.275Z

Reserved: 2026-09-08T21:49:12.396Z

Link: CVE-2026-87128

cve-icon Vulnrichment

Updated: 2026-09-15T22:47:20.383Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:18:59.820

Modified: 2026-09-21T18:06:01.827

Link: CVE-2026-87128

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T14:45:09Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function