Description
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-09-15
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to critical data
Action: Immediate Patch
AI Analysis

Impact

The Oracle Hyperion Data Relationship Management component is vulnerable in its access and security logic. Based on the description, it is inferred that a low‑privileged attacker can exploit the flaw and bypass authentication or authorization checks, enabling read access to all data available from the server. This leads to a confidentiality breach, where an attacker receives critical business information. No data integrity or availability impact is noted in the official description, but the scope change indicates that the vulnerability might also affect other Oracle products that have the same flaw.

Affected Systems

The vulnerability affects Oracle Hyperion Data Relationship Management version 11.2.26.0.000. The description also notes that the exploited weakness may change the scope to impact other Oracle products, though specific products are not listed in the advisory.

Risk and Exploitability

The CVSS v3.1 base score of 7.7 classifies the vulnerability as high severity, primarily affecting confidentiality. The EPSS score of less than 1% indicates a low probability of exploitation at the time of analysis, and the advisory is not yet listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote over HTTP, with low complexity and low privileges required. Because the flaw resides in the Access and security component, an attacker can bypass authentication or authorization controls to read all data exposed by the server. The scope change mentioned suggests that similar flaws in other Oracle products could amplify the impact.

Generated by OpenCVE AI on September 22, 2026 at 22:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch or upgrade to a fixed release of Oracle Hyperion Data Relationship Management that addresses the vulnerability.
  • Restrict HTTP access to the Hyperion servers using network firewalls or VPNs, ensuring only trusted internal networks can reach the system.
  • Review user permissions to enforce least privilege and ensure that only authorized users have access to sensitive data.
  • Monitor logs for authentication failures and unusual data requests, and set up alerts for repeated failed login attempts or unauthorized read requests.

Generated by OpenCVE AI on September 22, 2026 at 22:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Access via Access and Security Logic Flaw in Oracle Hyperion Data Relationship Management

Tue, 22 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863

Sun, 20 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 18 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Title Low Priv HTTP Exploit Enables Confidentiality Breach in Oracle Hyperion Data Relationship Management
Weaknesses CWE-284
CWE-285
CWE-287

Thu, 17 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Title Low Priv HTTP Exploit Enables Confidentiality Breach in Oracle Hyperion Data Relationship Management
Weaknesses CWE-284
CWE-285
CWE-287

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle hyperion Data Relationship Management
CPEs cpe:2.3:a:oracle:hyperion_data_relationship_management:11.2.26.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Data Relationship Management
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Hyperion Data Relationship Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-22T14:12:02.436Z

Reserved: 2026-09-08T21:49:12.397Z

Link: CVE-2026-87141

cve-icon Vulnrichment

Updated: 2026-09-22T14:11:44.495Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:01.383

Modified: 2026-09-22T19:45:05.897

Link: CVE-2026-87141

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T22:45:17Z

Weaknesses