CVE-2026-87142: High severity Oracle Oracle Hyperion Data Relationship Management vulnerability
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Hyperion Data Relationship Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle Hyperion Data Relationship Managementto a version that resolves this vulnerability.Fixed in 11.2.26.0.000
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Oracle Hyperion Data Relationship Management deployments running the supported affected version 11.2.26.0.000 are exposed if an attacker can reach the product over HTTPS. The attacker does not need authentication, but exploitation requires interaction by another person.
What could a successful attacker do?
A successful attack can allow unauthorized creation, deletion, or modification of critical data or all data accessible to Oracle Hyperion Data Relationship Management. It can also cause a partial denial of service.
Does an attacker need valid credentials or a complex exploit path?
No valid credentials are required, and the vulnerability is rated low attack complexity. However, the attacker needs network access via HTTPS and must induce human interaction from someone other than the attacker.