Junglewise Threat Intelligence

CVE-2026-70878: Oracle Hyperion Data Relationship Management unauthorized data access in Access and security

CVE-2026-70878 · Severity: high · CVSS 8.1 · Published 2026-08-18

Technologies: Oracle Hyperion Data Relationship Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Data Relationship Management is a system for managing data relationships and hierarchies in enterprise financial reporting environments. This vulnerability allows low-privileged users with network access to bypass access controls and create, modify, or delete critical data, or gain unauthorized read access to sensitive financial and operational information.

Technical details

This is an access control vulnerability in the Access and security component of Oracle Hyperion Data Relationship Management version 11.2.25.0.000. The vulnerability is easily exploitable via HTTP by a low-privileged authenticated attacker with network access, requiring no user interaction. Successful exploitation allows an attacker to bypass authorization controls, resulting in unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to all accessible data in the system. The CVSS 3.1 score of 8.1 reflects high confidentiality and integrity impacts with no availability impact.

Affected products

  • Oracle Hyperion Data Relationship Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats