PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-87141 Oracle CVE debrief

A vulnerability in Oracle Hyperion Data Relationship Management allows low-privileged attackers with network access via HTTP to compromise the product, potentially impacting additional products and allowing unauthorized access to critical data. This vulnerability, tracked as CVE-2026-87141, is exploitable and has a CVSS score of 7.7, indicating high severity. The vulnerability affects version 11.2.26.0.000 of Oracle Hyperion Data Relationship Management. Defenders should be aware of the potential for data breaches and take immediate action to verify exposure and assess impact.

Vendor
Oracle
Product
Hyperion Data Relationship Management
CVSS
HIGH 7.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-15
Original CVE updated
2026-09-22
Advisory published
2026-09-15
Advisory updated
2026-09-22

Who should care

Defenders responsible for Oracle Hyperion Data Relationship Management, network administrators, and security teams should assess exposure and potential impact. This includes operators managing affected product deployments, platform administrators, vulnerability management teams, and security teams responsible for data access controls and network segmentation. They should verify exposure, assess potential impact on additional products, review data access,

Why it matters

Defenders should care about CVE-2026-87141 because it allows low-privileged attackers to compromise Oracle Hyperion Data Relationship Management, potentially impacting additional products and allowing unauthorized access to critical data. Verification of exposure, assessment of potential impact, and review of data access controls and network segmentation are crucial.

  • Potential unauthorized access to critical data
  • Possible impact on additional products
  • Need for verification of exposure and data access controls
  • Importance of network segmentation and monitoring

Technical summary

The vulnerability in Oracle Hyperion Data Relationship Management 11.2.26.0.000 allows low-privileged attackers with network access via HTTP to compromise the product. Successful attacks can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. The CVSS 3.1 Base Score is 7.7, with a focus on confidentiality impacts. The vulnerability is easily exploitable and may significantly impact additional products, indicating a need for defenders to verify exposure and assess potential impact on additional products, with a focus on data access controls and network segmentation.

Defensive priority

Defenders should prioritize verifying exposure and assessing potential impact on additional products, with a focus on data access controls and network segmentation.

Recommended defensive actions

  • Verify exposure of Oracle Hyperion Data Relationship Management 11.2.26.0.000 in managed environments.
  • Review the official CVE Program record and NIST NVD detail page for guidance on affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Monitor for unauthorized access attempts and review data access controls and network segmentation.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, its CVSS score, and potential impacts. However, additional information on affected versions, exploitation, and remediation is limited.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-87141 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-87141

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-87141 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87141

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.