Description
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

A flaw in the access and security component of Oracle Hyperion Data Relationship Management allows an unauthenticated attacker with network access to the SOAP interface to cause a hang or a repeatable crash of the application, which results in a complete denial of service. The vulnerability is classified as CWE‑400 and carries a CVSS 3.1 base score of 7.5, indicating a high availability impact.

Affected Systems

The affected product is Oracle Hyperion Data Relationship Management, version 11.2.26.0.000, supplied by Oracle Corporation.

Risk and Exploitability

Because the flaw can be triggered from the network without authentication and the EPSS score is less than 1 %, the practical likelihood of exploitation is considered low, but the impact is severe if an attack succeeds. The vulnerability is not listed in CISA’s KEV catalog; however, an attacker who controls the remote SOAP endpoint could repeatedly crash the application, causing significant downtime.

Generated by OpenCVE AI on September 18, 2026 at 15:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Oracle patch for Hyperion Data Relationship Management 11.2.26.0.000 to address the denial‑of‑service flaw
  • Restrict network access to the SOAP service, allowing only trusted hosts or VPN connections to send requests
  • If the SOAP interface is not required for business operations, consider disabling it or isolating it behind a firewall to prevent unauthorized traffic

Generated by OpenCVE AI on September 18, 2026 at 15:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated SOAP-based Denial of Service in Oracle Hyperion Data Relationship Management

Wed, 16 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated SOAP-based Denial of Service in Oracle Hyperion Data Relationship Management

Wed, 16 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle hyperion Data Relationship Management
CPEs cpe:2.3:a:oracle:hyperion_data_relationship_management:11.2.26.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Data Relationship Management
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Oracle Hyperion Data Relationship Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T23:14:52.680Z

Reserved: 2026-09-08T21:49:12.397Z

Link: CVE-2026-87138

cve-icon Vulnrichment

Updated: 2026-09-15T23:12:44.031Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:00.930

Modified: 2026-09-22T18:00:03.077

Link: CVE-2026-87138

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T15:15:06Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption