Junglewise Threat Intelligence

CVE-2026-70877: Oracle Hyperion Data Relationship Management privilege escalation in access and security

CVE-2026-70877 · Severity: high · CVSS 8.8 · Published 2026-08-18

Technologies: Oracle Hyperion Data Relationship Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Data Relationship Management is an enterprise financial planning and consolidation platform used by organizations to manage complex financial data relationships. A vulnerability in its access control and security component allows a low-privileged authenticated user to gain complete control over the system, potentially compromising all data confidentiality, integrity, and system availability.

Technical details

This is a privilege escalation vulnerability in the access and security component of Oracle Hyperion Data Relationship Management (DRM) version 11.2.25.0.000. The flaw allows a low-privileged attacker with valid network credentials to authenticate via HTTP and escalate privileges without user interaction. Successful exploitation results in complete compromise of the application, granting the attacker full read, write, and administrative control over the system. The vulnerability is easily exploitable and requires only network access and valid credentials; there is no indication of active exploitation in the wild at this time.

Affected products

  • Oracle Hyperion Data Relationship Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats