PatchSiren cyber security CVE debrief
CVE-2026-87141 Oracle CVE debrief
A vulnerability in Oracle Hyperion Data Relationship Management allows low-privileged attackers with network access via HTTP to compromise the product, potentially impacting additional products and allowing unauthorized access to critical data. This vulnerability, tracked as CVE-2026-87141, is exploitable and has a CVSS score of 7.7, indicating high severity. The vulnerability affects version 11.2.26.0.000 of Oracle Hyperion Data Relationship Management. Defenders should be aware of the potential for data breaches and take immediate action to verify exposure and assess impact.
- Vendor
- Oracle
- Product
- Hyperion Data Relationship Management
- CVSS
- HIGH 7.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-15
- Original CVE updated
- 2026-09-22
- Advisory published
- 2026-09-15
- Advisory updated
- 2026-09-22
Who should care
Defenders responsible for Oracle Hyperion Data Relationship Management, network administrators, and security teams should assess exposure and potential impact. This includes operators managing affected product deployments, platform administrators, vulnerability management teams, and security teams responsible for data access controls and network segmentation. They should verify exposure, assess potential impact on additional products, review data access,
Why it matters
Defenders should care about CVE-2026-87141 because it allows low-privileged attackers to compromise Oracle Hyperion Data Relationship Management, potentially impacting additional products and allowing unauthorized access to critical data. Verification of exposure, assessment of potential impact, and review of data access controls and network segmentation are crucial.
- Potential unauthorized access to critical data
- Possible impact on additional products
- Need for verification of exposure and data access controls
- Importance of network segmentation and monitoring
Technical summary
The vulnerability in Oracle Hyperion Data Relationship Management 11.2.26.0.000 allows low-privileged attackers with network access via HTTP to compromise the product. Successful attacks can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. The CVSS 3.1 Base Score is 7.7, with a focus on confidentiality impacts. The vulnerability is easily exploitable and may significantly impact additional products, indicating a need for defenders to verify exposure and assess potential impact on additional products, with a focus on data access controls and network segmentation.
Defensive priority
Defenders should prioritize verifying exposure and assessing potential impact on additional products, with a focus on data access controls and network segmentation.
Recommended defensive actions
- Verify exposure of Oracle Hyperion Data Relationship Management 11.2.26.0.000 in managed environments.
- Review the official CVE Program record and NIST NVD detail page for guidance on affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Monitor for unauthorized access attempts and review data access controls and network segmentation.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, its CVSS score, and potential impacts. However, additional information on affected versions, exploitation, and remediation is limited.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-87141 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-87141
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-87141 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87141
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.oracle.com/security-alerts/cspusep2026.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.