Description
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-09-15
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access and Modification
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in Hyperion Data Relationship Management's access and security component. It permits an unauthenticated attacker who can reach the system over SMTP to alter access controls, thereby creating, deleting, or modifying access rights to critical data. This also allows the attacker to gain unauthorized access to the data itself, potentially obtaining full visibility over all stored assets. The weakness aligns with improper authentication and access control weaknesses, allowing breaches of confidentiality and integrity.

Affected Systems

Affected systems are Oracle Hyperion Data Relationship Management 11.2.26.0.000. Only this specific release is impacted, and all deployments running this version are susceptible regardless of their network posture.

Risk and Exploitability

The base CVSS score of 7.4 reflects high confidentiality and integrity impact with a high attack complexity. EPSS indicates a very low probability of exploitation (<1%), and the vulnerability is not listed in CISA KEV catalog. Despite the low exploitation likelihood, the attack vector requires only network access via SMTP, and the absence of authentication makes exploitation straightforward once the attacker reaches the environment.

Generated by OpenCVE AI on September 20, 2026 at 06:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor-provided patch for Oracle Hyperion Data Relationship Management 11.2.26.0.000.
  • Block inbound SMTP traffic to the Hyperion servers using firewall or network segmentation to prevent unauthenticated access.
  • Enforce stricter access controls to the Hyperion application by configuring authentication mechanisms and removing default or unused accounts.

Generated by OpenCVE AI on September 20, 2026 at 06:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Title Unauthorized SMTP-Based Access Control Bypass in Oracle Hyperion Data Relationship Management

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated SMTP-Based Access Control Bypass in Oracle Hyperion Data Relationship Management
Weaknesses CWE-287
CWE-306

Wed, 16 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated SMTP-Based Access Control Bypass in Oracle Hyperion Data Relationship Management
Weaknesses CWE-284
CWE-287
CWE-306

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle hyperion Data Relationship Management
CPEs cpe:2.3:a:oracle:hyperion_data_relationship_management:11.2.26.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Data Relationship Management
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Hyperion Data Relationship Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-18T18:23:45.700Z

Reserved: 2026-09-08T21:49:12.396Z

Link: CVE-2026-87130

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:00.037

Modified: 2026-09-22T17:28:50.063

Link: CVE-2026-87130

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T06:45:17Z

Weaknesses