PatchSiren cyber security CVE debrief
CVE-2026-87138 Oracle CVE debrief
CVE-2026-87138 is a high-severity vulnerability in Oracle Hyperion Data Relationship Management 11.2.26.0.000, classified as easily exploitable by unauthenticated attackers with network access via SOAP, potentially causing a hang or frequently repeatable crash (complete DOS). Defenders should prioritize verifying exposure and assessing network access controls to SOAP. The vulnerability's CVSS 3.1 Base Score is 7.5, indicating high severity with significant availability impacts. This debrief provides an executive overview of the affected product, vulnerability class, likely operational impact, and source-confidence limits based on the CVE record and NVD entry.
- Vendor
- Oracle
- Product
- Hyperion Data Relationship Management
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-15
- Original CVE updated
- 2026-09-22
- Advisory published
- 2026-09-15
- Advisory updated
- 2026-09-22
Who should care
Defenders responsible for Oracle Hyperion Data Relationship Management deployments, vulnerability management teams, and security teams should assess exposure and verify network access controls. Operators of affected systems should prioritize remediation and review compensating controls. Platform administrators and security teams should review the official advisory and plan for vendor-supported updates or mitigations.
Why it matters
CVE-2026-87138 is a high-severity vulnerability in Oracle Hyperion Data Relationship Management that allows unauthenticated attackers to potentially cause a denial of service. Defenders should prioritize verifying exposure and assessing network access controls.
- Potential unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Data Relationship Management
- Verification of network access controls to SOAP is necessary
Technical summary
The vulnerability in Oracle Hyperion Data Relationship Management 11.2.26.0.000 allows unauthenticated attackers with network access via SOAP to compromise the product, potentially causing a hang or frequently repeatable crash (complete DOS). The CVSS 3.1 Base Score is 7.5, indicating high severity with significant availability impacts. Defenders should prioritize verifying exposure and assessing network access controls to SOAP. The vulnerability is classified as easily exploitable, and its technical framing is based on source-grounded information.
Defensive priority
Defenders should prioritize verifying exposure of Oracle Hyperion Data Relationship Management 11.2.26.0.000 and assessing network access controls.
Recommended defensive actions
- Verify exposure of Oracle Hyperion Data Relationship Management 11.2.26.0.000 in managed environments.
- Review and apply vendor advisory from Oracle through normal change control.
- Assess network access controls to SOAP for exposed systems.
- Review compensating controls for exposed systems while remediation is scheduled.
- Check relevant monitoring, detection, and logs for exposed assets.
- Track exceptions and retest remediated assets.
- Plan for vendor-supported updates or mitigations.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability in Oracle Hyperion Data Relationship Management 11.2.26.0.000. The vendor advisory from Oracle is also available. Defenders should verify exposure and assess network access controls to SOAP. Evidence limits are based on source-provided information, and known affected scope is limited to the specified product version. Unknown affected scope may exist, and defenders should review the official advisory for further details.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-87138 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-87138
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-87138 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87138
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.oracle.com/security-alerts/cspusep2026.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.