CVE-2026-87145
Executive Summary
Oracle Hyperion Data Relationship Management (v11.2.26.0.000) is vulnerable to an unauthenticated HTTP-based exploit that allows attackers to read, modify, or delete data and cause a partial denial of service. The flaw resides in the Access and Security component, enabling unauthorized access to sensitive data and potential data integrity compromise. CVSS v3.1 score 7.3 (L/C, L/I, L/A). Not listed in CISA KEV.
Authoritative CVE Metadata - CVSS Base Score: 7.3 (HIGH) - Published: 2026-09-15T20:19:01.840 - Last Modified: 2026-09-21T01:16:29.637
Original Description: Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Data Relationship Management accessible data as well as unauthorized read access to a subset of Oracle Hyperion Data Relationship Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).
"If you surrender to the wind, you can ride it."
— Toni Morrison