Description
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (availability)
Action: Patch
AI Analysis

Impact

A flaw in the Access and security component of Oracle Hyperion Data Relationship Management permits an unauthenticated attacker to trigger a persistent denial of service over HTTP. The vulnerability is a manifestation of uncontrolled resource consumption, classified as CWE-400, leading the application to hang or crash so that it cannot respond to legitimate requests.

Affected Systems

Oracle Corporation’s Hyperion Data Relationship Management, version 11.2.26.0.000, is the only supported build listed as affected. No other versions or components were identified as vulnerable.

Risk and Exploitability

The CVSS score of 7.5 indicates a high impact on availability, while the EPSS score of less than 1% suggests a low probability of exploitation at this time. Because the flaw is exploitable without authentication and can be triggered via standard HTTP requests, it poses a significant risk to organizations that expose the application to the network. The vulnerability is not listed in CISA KEV, but its availability impact and the lack of authentication prerequisites increase its urgency for remediation.

Generated by OpenCVE AI on September 18, 2026 at 15:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Oracle security patch that addresses the unauthenticated HTTP DoS flaw in Hyperion Data Relationship Management version 11.2.26.0.000.
  • Restrict inbound HTTP traffic to trusted IP ranges or place the application behind a VPN or firewall that requires authentication, thereby limiting attacker access.
  • Configure monitoring of request rates and application responsiveness and set alerts for abnormal traffic patterns or crashes to detect and mitigate denial‑of‑service attempts early.

Generated by OpenCVE AI on September 18, 2026 at 15:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Denial of Service in Oracle Hyperion Data Relationship Management

Wed, 16 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Denial of Service in Oracle Hyperion Data Relationship Management

Wed, 16 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle hyperion Data Relationship Management
CPEs cpe:2.3:a:oracle:hyperion_data_relationship_management:11.2.26.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Data Relationship Management
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Oracle Hyperion Data Relationship Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T23:14:52.525Z

Reserved: 2026-09-08T21:49:12.398Z

Link: CVE-2026-87148

cve-icon Vulnrichment

Updated: 2026-09-15T23:12:40.304Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:02.190

Modified: 2026-09-22T19:20:07.567

Link: CVE-2026-87148

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T15:15:06Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption