Junglewise Threat Intelligence

CVE-2026-70879: Oracle Hyperion Data Relationship Management privilege escalation in access control

CVE-2026-70879 · Severity: high · CVSS 7.8 · Published 2026-08-18

Technologies: Oracle Hyperion Data Relationship Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Data Relationship Management is a financial planning and data management tool used by enterprises to consolidate and analyze business data. A vulnerability in access controls allows a low-privileged user with local system access to gain full control of the system, potentially compromising sensitive financial and operational data across multiple interconnected systems.

Technical details

This is a privilege escalation vulnerability in the access and security component of Oracle Hyperion Data Relationship Management. The vulnerability requires local access (AV:L) and low-level privileges but is difficult to exploit (AC:H). An authenticated attacker with logon access to the infrastructure can escalate privileges to compromise the entire system. The vulnerability has a scope change (S:C), meaning successful exploitation can impact other products and systems connected to the Hyperion environment. The attack requires no user interaction (UI:N) and results in complete compromise of confidentiality, integrity, and availability.

Affected products

  • Oracle Hyperion Data Relationship Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats