PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-87142 Oracle CVE debrief

CVE-2026-87142 is a high-severity vulnerability in Oracle Hyperion Data Relationship Management, a component of Oracle Hyperion. The vulnerability is classified as easily exploitable, allowing unauthenticated attackers with network access via HTTPS to compromise the system. Successful attacks require human interaction and can result in unauthorized creation, deletion, or modification access to critical data and partial denial of service. The affected version is 11.2.26.0.000. Oracle Hyperion Data Relationship Management users and administrators should assess exposure and implement compensating controls. The CVSS 3.1 Base Score is 7.1, indicating high integrity and availability The

Vendor
Oracle
Product
Hyperion Data Relationship Management
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-15
Original CVE updated
2026-09-22
Advisory published
2026-09-15
Advisory updated
2026-09-22

Who should care

Oracle Hyperion Data Relationship Management users and administrators should assess exposure and implement compensating controls. The vulnerability requires immediate attention from users and administrators. Defenders should prioritize assessment and remediation efforts. The vulnerability allows unauthenticated attackers with network access to potentially modify critical data and cause partial denial of service.

Why it matters

CVE-2026-87142 is a high-severity vulnerability in Oracle Hyperion Data Relationship Management that requires immediate attention from users and administrators. The vulnerability allows unauthenticated attackers with network access to potentially modify critical data and cause partial denial of service. While exploitation requires human interaction, defenders should prioritize assessment and remediation efforts.

  • Potential unauthorized data modification
  • Partial denial of service (DOS) risk
  • Requires verification of affected versions and remediation

Technical summary

Easily exploitable vulnerability in Oracle Hyperion Data Relationship Management, version 11.2.26.0.000, allows unauthenticated attacker with network access via HTTPS to compromise the system. Successful attacks require human interaction and can result in unauthorized creation, deletion or modification access to critical data and partial denial of service. The CVSS 3.1 Base Score is 7.1, indicating high integrity and availability impacts. CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L). The vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Hyperion Data Relationship Management.

Defensive priority

High priority for Oracle Hyperion Data Relationship Management users

Recommended defensive actions

  • Assess exposure of Oracle Hyperion Data Relationship Management version 11.2.26.0.000
  • Verify network access controls to HTTPS
  • Implement compensating controls for human interaction
  • Review and apply vendor remediation
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

Official CVE Program and NVD records confirm vulnerability in Oracle Hyperion Data Relationship Management, version 11.2.26.0.000. Human interaction is required for successful attacks. The CVE record was published on 2026-09-15T20:19:01.497Z and has not been modified since then. The vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Hyperion Data Relationship Management. Successful attacks require human interaction from a person other than the attacker.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-87142 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-87142

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-87142 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87142

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.