Description
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-09-15
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Modification and Access
Action: Patch Immediately
AI Analysis

Impact

The flaw lives in the Access and Security component of Oracle Hyperion Data Relationship Management and permits a high privileged attacker with network access via HTTP to create, delete or alter critical data. Affected data may include all records accessible through the product; confidentiality and integrity are compromised. Because the vulnerability can change the overall scope, other Oracle Hyperion applications may also be impacted.

Affected Systems

Oracle Hyperion Data Relationship Management, version 11.2.26.0.000, is affected. The vulnerability may also impact additional Oracle Hyperion products due to a scope change that extends the reach of the flaw beyond the original product.

Risk and Exploitability

The CVSS 3.1 base score of 7.7 signals high overall impact, while the EPSS score of less than 1% indicates that exploitation is at present considered unlikely. The vulnerability is not listed in the CISA KEV catalog. Its remote network exposure and requirement for high privileged access mean that the risk is non‑negligible even though successful exploitation is rare. If an attacker succeeds, they could fully subvert data integrity and availability within the affected Hyperion environment.

Generated by OpenCVE AI on September 20, 2026 at 06:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the security update for Oracle Hyperion Data Relationship Management 11.2.26.0.000 as distributed by Oracle (see the Oracle security alert for detail).
  • Restrict HTTP access to the Hyperion services by limiting connections to trusted IP addresses or internal networks through firewall rules.
  • Implement logging and monitoring of Hyperion database activities to detect unauthorized data modifications and access attempts.

Generated by OpenCVE AI on September 20, 2026 at 06:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Title High-privileged HTTP Exploit Compromises Oracle Hyperion Data Relationship Management
Weaknesses CWE-269
CWE-284

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title High Privilege Network Vulnerability Allowing Unauthorized Data Modification in Oracle Hyperion Data Relationship Management
Weaknesses CWE-284

Wed, 16 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Title High Privilege Network Vulnerability Allowing Unauthorized Data Modification in Oracle Hyperion Data Relationship Management
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle hyperion Data Relationship Management
CPEs cpe:2.3:a:oracle:hyperion_data_relationship_management:11.2.26.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Data Relationship Management
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Hyperion Data Relationship Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-20T23:53:13.820Z

Reserved: 2026-09-08T21:49:12.398Z

Link: CVE-2026-87147

cve-icon Vulnrichment

Updated: 2026-09-20T23:45:42.554Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:02.063

Modified: 2026-09-22T19:37:48.630

Link: CVE-2026-87147

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T07:00:08Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control