PatchSiren cyber security CVE debrief
CVE-2026-87129 Oracle CVE debrief
A critical vulnerability exists in Oracle Hyperion Data Relationship Management 11.2.26.0.000. This easily exploitable vulnerability allows unauthenticated attackers with network access via HTTP to compromise the product, potentially leading to unauthorized creation, deletion, or modification of critical data or complete access to all accessible data.
- Vendor
- Oracle
- Product
- Hyperion Data Relationship Management
- CVSS
- CRITICAL 9.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-15
- Original CVE updated
- 2026-09-22
- Advisory published
- 2026-09-15
- Advisory updated
- 2026-09-22
Who should care
Defenders responsible for Oracle Hyperion Data Relationship Management systems, especially those with network exposure, should assess their systems for this vulnerability and apply patches or mitigations as necessary. IT security teams and administrators managing Oracle Hyperion Data Relationship Management should prioritize remediation due to the high severity and potential impact of this vulnerability.
Why it matters
CVE-2026-87129 is a critical vulnerability in Oracle Hyperion Data Relationship Management that allows unauthenticated network attacks, potentially leading to data tampering or unauthorized access. Defenders should prioritize patching due to the high CVSS score of 9.1 and the potential for significant data exposure or disruption.
- Potential unauthorized data modifications or access.
- Risk of complete data exposure or tampering.
- Need for immediate patching or mitigation to prevent exploitation.
- Potential disruption to critical business processes relying on Oracle Hyperion Data Relationship Management.
Technical summary
The vulnerability in Oracle Hyperion Data Relationship Management (component: Access and security) allows unauthenticated attackers with network access via HTTP to compromise the product. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data, as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. The CVSS 3.1 Base Score is 9.1, indicating a Critical severity level.
Defensive priority
High priority remediation is recommended for systems using Oracle Hyperion Data Relationship Management 11.2.26.0.000, as this vulnerability has a high CVSS score of 9.1 and can be exploited over the network without authentication.
Recommended defensive actions
- Review and apply Oracle's security patches for Hyperion Data Relationship Management 11.2.26.0.000.
- Restrict network access to Oracle Hyperion Data Relationship Management to only necessary personnel.
- Monitor Oracle Hyperion Data Relationship Management systems for unauthorized access or data modifications.
- Verify that no unauthorized changes have been made to critical data.
- Perform a thorough review of system configurations and network exposure to identify potential vulnerabilities.
- Implement additional monitoring and logging to detect potential security incidents related to this vulnerability.
- Inventory and track all Oracle Hyperion Data Relationship Management systems to ensure comprehensive remediation.
Evidence notes
The CVE and NVD records provide details on this vulnerability, including its CVSS score, affected versions, and potential impacts. Oracle has also released a security advisory related to this vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-87129 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-87129
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-87129 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87129
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.oracle.com/security-alerts/cspusep2026.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.