Description
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N).
Published: 2026-09-15
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data access and modification
Action: Patch promptly
AI Analysis

Impact

This vulnerability resides in the access and security component of Oracle Hyperion Data Relationship Management. It allows an attacker with high privileges and network access to HTTP traffic to gain unauthorized access to all data stored in the application and to edit, insert, or delete that data. The impact includes confidentiality loss for critical data and potential integrity compromise.

Affected Systems

Oracle Corporation’s Hyperion Data Relationship Management product, version 11.2.26.0.000, is affected. No other vendor variants or versions are indicated at this time.

Risk and Exploitability

The CVSS core score of 7.6 (AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N) indicates high confidentiality impact and a lower integrity impact, with a scope change making the vulnerability affect more than the initially affected component. The EPSS score is very low (< 1%), meaning that the demonstrated exploitation probability is small, but the attack can still be carried out by a skilled adversary with network access. The vulnerability is not listed in CISA’s KEV catalog, implying no known widespread exploitation. Attackers would need to reach the application over HTTP, supply crafted requests, and exploit the privilege escalation to gain full administrative control of the data stored within Hyperion.

Generated by OpenCVE AI on September 20, 2026 at 06:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Oracle’s latest security patch for Hyperion Data Relationship Management that fixes the access and security flaw
  • Restrict HTTP access to the application by using a firewall or VPN so that only trusted internal hosts can reach it
  • Regularly monitor application logs for abnormal data modification attempts and consider implementing application-layer access controls to mitigate unauthorized changes

Generated by OpenCVE AI on September 20, 2026 at 06:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation and Data Modification via HTTP in Oracle Hyperion Data Relationship Management
Weaknesses CWE-284

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title High Privileged HTTP Vulnerability Leading to Unauthorized Data Access in Oracle Hyperion Data Relationship Management
Weaknesses CWE-200
CWE-284

Wed, 16 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Title High Privileged HTTP Vulnerability Leading to Unauthorized Data Access in Oracle Hyperion Data Relationship Management
Weaknesses CWE-200
CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N).
First Time appeared Oracle
Oracle hyperion Data Relationship Management
CPEs cpe:2.3:a:oracle:hyperion_data_relationship_management:11.2.26.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Data Relationship Management
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Oracle Hyperion Data Relationship Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-21T19:36:21.870Z

Reserved: 2026-09-08T21:49:12.397Z

Link: CVE-2026-87133

cve-icon Vulnrichment

Updated: 2026-09-21T19:36:12.835Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:00.367

Modified: 2026-09-22T19:40:07.620

Link: CVE-2026-87133

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T06:45:17Z

Weaknesses