Junglewise Threat Intelligence

CVE-2026-70875: Oracle Hyperion Data Relationship Management privilege escalation in access control

CVE-2026-70875 · Severity: high · CVSS 7.5 · Published 2026-08-18

Technologies: Oracle Hyperion Data Relationship Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Data Relationship Management is an enterprise data modeling and governance platform used by organizations to manage complex data relationships and hierarchies. A vulnerability in its access control component allows a low-privileged attacker with network access to gain complete control over the system, compromising all data confidentiality, integrity, and availability.

Technical details

This vulnerability exists in the access and security component of Oracle Hyperion Data Relationship Management version 11.2.25.0.000. It is a privilege escalation vulnerability accessible via HTTP that can be exploited by low-privileged attackers with network access. While classified as difficult to exploit (requiring specific preconditions such as high attack complexity), successful exploitation results in complete system compromise with full confidentiality, integrity, and availability impact. The vulnerability has not been reported as actively exploited in the wild as of the publication date.

Affected products

  • Oracle Hyperion Data Relationship Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats