Junglewise Threat Intelligence

CVE-2026-70874: Oracle Hyperion Data Relationship Management privilege escalation in Access and security

CVE-2026-70874 · Severity: high · CVSS 8.8 · Published 2026-08-18

Technologies: Oracle Hyperion Data Relationship Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Data Relationship Management is an enterprise application used to manage hierarchical data structures and relationships in large organizations. A vulnerability in the access control component allows a low-privileged authenticated user to escalate privileges and gain complete control of the system, risking exposure or manipulation of sensitive financial and operational data stored within.

Technical details

This is a privilege escalation vulnerability in the Access and security component of Oracle Hyperion Data Relationship Management version 11.2.25.0.000. The vulnerability allows a low-privileged attacker with network access via HTTP to escalate privileges and compromise the system. The attack requires authentication but no additional user interaction is needed (CVSS vector shows PR:L, UI:N). Successful exploitation results in complete system compromise with impacts to confidentiality, integrity, and availability. The vulnerability was reported but is not known to be actively exploited in the wild as of the publication date.

Affected products

  • Oracle Hyperion Data Relationship Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats