Description
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Full System Compromise
Action: Immediate Patch
AI Analysis

Impact

Oracle Hyperion Data Relationship Management contains a flaw in its access and security component that allows an attacker with low privileges and simple network access via HTTP to compromise the application. Successful exploitation can lead to a full takeover of the product, resulting in loss of confidentiality, integrity, and availability for all data managed by the system.

Affected Systems

The vulnerability affects Oracle Hyperion Data Relationship Management version 11.2.26.0.000. No other affected versions are currently listed in the available data.

Risk and Exploitability

The CVSS 3.1 base score of 7.5 indicates a high severity, while the EPSS score of <1% reflects a low probability of exploitation in the current threat landscape. The vulnerability is not yet listed in CISA’s KEV catalog. The likely attack vector is a remote, network-based HTTP request; an attacker requires only low privileges to successfully compromise the application and potentially gain unrestricted access to the Hyperion instance.

Generated by OpenCVE AI on September 17, 2026 at 23:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official Oracle patch or upgrade to a non‑vulnerable version of Hyperion Data Relationship Management.
  • Restrict network access to the Hyperion service by configuring firewalls or VPNs so that only trusted hosts can reach the HTTP interface.
  • Enforce strict authentication and review application access controls to ensure that users have no more permissions than necessary.

Generated by OpenCVE AI on September 17, 2026 at 23:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Title Access Control Vulnerability in Oracle Hyperion Data Relationship Management Allowing Full Product Takeover
Weaknesses CWE-284

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Title Access Control Vulnerability in Oracle Hyperion Data Relationship Management Allowing Full Product Takeover
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle hyperion Data Relationship Management
CPEs cpe:2.3:a:oracle:hyperion_data_relationship_management:11.2.26.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Data Relationship Management
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Hyperion Data Relationship Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:00:22.147Z

Reserved: 2026-09-08T21:49:12.397Z

Link: CVE-2026-87139

cve-icon Vulnrichment

Updated: 2026-09-17T12:57:56.939Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:01.107

Modified: 2026-09-22T18:00:39.857

Link: CVE-2026-87139

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T23:45:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management