Junglewise Threat Intelligence

CVE-2026-70876: Oracle Hyperion Data Relationship Management access control bypass

CVE-2026-70876 · Severity: critical · CVSS 9.1 · Published 2026-08-18

Technologies: Oracle Hyperion Data Relationship Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Data Relationship Management is a critical enterprise financial planning and data integration system used by large organizations. A vulnerability in the access and security component allows a high-privileged attacker with network access to completely take over the system, potentially compromising sensitive financial data and operations across connected systems.

Technical details

This is an access control vulnerability in the Oracle Hyperion Data Relationship Management component (version 11.2.25.0.000) exploitable over HTTPS by a high-privileged attacker with network access. The vulnerability permits complete compromise of the affected system—including confidentiality, integrity, and availability impacts—and has a scope change designation indicating attacks may significantly impact additional interconnected products. The attack requires high privilege level but no user interaction; patches or workarounds availability is not detailed in available sources.

Affected products

  • Oracle Hyperion Data Relationship Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats