Junglewise Threat Intelligence

CVE-2026-70872: Oracle Hyperion Data Relationship Management authentication bypass in Access and security

CVE-2026-70872 · Severity: critical · CVSS 9.1 · Published 2026-08-18

Technologies: Oracle Hyperion Data Relationship Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Data Relationship Management is a data integration and governance platform used by enterprises to manage critical business information. An unauthenticated attacker can bypass security controls and gain complete access to the system over the network, allowing them to view, modify, or delete sensitive business data without authorization.

Technical details

This is an authentication bypass vulnerability in the Access and security component of Oracle Hyperion Data Relationship Management version 11.2.25.0.000. The vulnerability is easily exploitable and requires no user interaction; an unauthenticated attacker with network access via HTTP can bypass authentication controls to gain unauthorized access. Successful exploitation allows complete read and write access to critical data stored in the system. The vulnerability affects all accessible data in the platform and has both confidentiality and integrity impacts.

Affected products

  • Oracle Hyperion Data Relationship Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats