External risk intelligence

Oracle Hyperion Data Relationship Management Access Control Bypass

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-87128

The product is an enterprise data management application typically deployed within internal corporate networks. While the vulnerability is reachable via HTTP, it is not a standard internet-facing edge service or public-facing portal by design, though accidental or intentional exposure in some deployments remains a possibility.

Authentication Bypass

Oracle Hyperion Data Relationship Management

11.2.26.0.000

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in Oracle Hyperion Data Relationship Management could allow an attacker to gain unauthorized access to critical data, or create, delete, or modify it, due to an easily exploitable flaw.

  • Unauthorized access to sensitive data is possible.
  • Confirms exposure of critical financial data systems.
  • Assess Hyperion's role in your financial reporting.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending specially crafted network requests to the Oracle Hyperion Data Relationship Management system. This allows them to bypass authentication and gain unauthorized access to sensitive data. If successful, the attacker can manipulate critical information within the system.

  • Attacker has network access.
  • Unauthenticated HTTP requests trigger vulnerability.
  • Leads to unauthorized data access and modification.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in Oracle Hyperion Data Relationship Management could allow an attacker to gain unauthorized access to critical data, potentially leading to its unauthorized creation, deletion, or modification. This risk exists when the product is accessible over a network via HTTP and is not protected by additional security measures.

  • Critical data within the application.
  • Network access via HTTP.
  • Unauthorized data modification or deletion.

Operational Fix

Recommended remediation, mitigation, and detection steps

Owners of Oracle Hyperion Data Relationship Management applications and the supporting infrastructure teams are likely responsible for addressing this vulnerability. The first practical step is to identify all instances of the affected product, confirm their network reachability and business criticality, and then engage with the accountable owner to plan remediation.

  • Own the issue and confirm exposure.
  • Verify product inventory and reachability.
  • Plan remediation and coordinate with vendors.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Hyperion Data Relationship Management?

Oracle Hyperion Data Relationship Management is an enterprise application used by organizations to manage complex master data and hierarchies across different financial systems. It serves as a central hub to ensure data consistency, helping businesses maintain accurate reporting and alignment across their financial and operational environments.

What does CVE-2026-87128 mean for data security?

This vulnerability involves improper authentication and a missing authentication requirement, classified as CWE-287 and CWE-306. Essentially, the system fails to verify the identity of someone connecting to it. This allows an attacker to interact with the software as if they were a legitimate, logged-in user, granting them the ability to read, change, or delete sensitive business data without needing a password.

How is this vulnerability triggered?

An attacker triggers this flaw by sending specifically crafted HTTP requests to the application over the network. It does not require any prior authentication or special user permissions to execute. However, this does not mean simply visiting a webpage in a browser will trigger the issue; the attack requires targeted, unauthorized network communication aimed at the system's access control functions.

Is my system at risk if it is not on the internet?

According to Halo Surface Signal, this software is typically deployed within internal corporate networks and is not intended to be a public-facing service. While this limits the number of potential attackers, the risk remains if the application is accidentally or intentionally exposed to broader network segments where unauthorized users could reach it via HTTP.

How should I begin addressing this security issue?

Start by identifying every instance of Hyperion Data Relationship Management running in your environment. Once you have a complete inventory, determine which instances are reachable over your network and assess their business importance. Use this information to coordinate with your technical teams to prioritize these assets for vendor-supplied updates or security mitigations.

References