External risk intelligence

Oracle Hyperion Data Relationship Management Access Control Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-87129

Oracle Hyperion Data Relationship Management is typically an enterprise-internal backend application used for master data management. While the vulnerability is reachable via HTTP and does not require authentication, such systems are generally deployed within internal corporate networks and are not intended to be exposed directly to the public internet.

Authentication Bypass

Oracle Hyperion Data Relationship Management

11.2.26.0.000

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been identified in Oracle Hyperion Data Relationship Management, a product used for managing critical business data. This issue could allow unauthorized access to alter or view sensitive information. The primary concern is to confirm if our environment is exposed to this type of technology and if it is subject to this vulnerability.

  • Unauthenticated access to critical data.
  • Confirming relevance and exposure is key.
  • Understand potential impact on sensitive data.

Attack Path

How an attacker could exploit the issue

An attacker could reach this vulnerability by accessing the Oracle Hyperion Data Relationship Management product over a network. Because it is exposed via HTTP and requires no authentication, an attacker could potentially compromise the system and gain unauthorized access to or modify critical data.

  • No authentication required
  • Network access via HTTP
  • Unauthorized data access or modification

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access could compromise Oracle Hyperion Data Relationship Management, potentially leading to unauthorized modifications or access to critical data. This vulnerability can affect the integrity and confidentiality of data managed by the application.

  • Critical data within the system.
  • Network access via HTTP.
  • Unauthorized data modification or access.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Oracle Hyperion Data Relationship Management product, specifically the Access and security component, is susceptible to a critical vulnerability. This issue requires immediate attention from teams responsible for application ownership, infrastructure, and security. The first practical step involves identifying all instances of the affected technology, confirming their network reachability and business criticality, and then locating the accountable owner to initiate a risk-based remediation plan.

  • Application and infrastructure teams own the issue.
  • Verify network exposure and business criticality.
  • Plan remediation based on confirmed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Hyperion Data Relationship Management?

It is a specialized enterprise application used for master data management. Organizations use it to maintain consistent business data across various systems, ensuring that information remains accurate and synchronized throughout the company’s infrastructure.

What does CVE-2026-87129 mean by improper authentication?

This vulnerability involves missing or incorrectly implemented authentication mechanisms. It is classified under CWE-287 and CWE-306, meaning the software fails to verify the identity of a user or fails to enforce authentication entirely, allowing unauthenticated attackers to interact with protected functions.

How does an attacker trigger this vulnerability?

An attacker triggers this by sending unauthorized HTTP requests to the application over the network. It does not require any credentials or special access to succeed. Simply connecting to the HTTP service is enough to attempt to view, create, or modify data; internal administrative actions performed by verified users do not trigger this bug.

Is my instance affected by this vulnerability?

According to Halo Surface Signal, this software is typically deployed as an internal backend system. While it is technically reachable via HTTP, it is generally not intended for public internet access. You should evaluate whether your instance is reachable from untrusted networks, which would significantly increase the risk level.

What should I do to address this risk?

Begin by identifying all running instances of the affected version (11.2.26.0.000) within your environment. Once located, coordinate with the infrastructure and application owners to assess the business criticality of those systems and initiate a risk-based plan to secure the installation.

References