Junglewise Threat Intelligence

CVE-2026-70880: Oracle Hyperion Data Relationship Management authentication bypass

CVE-2026-70880 · Severity: critical · CVSS 10 · Published 2026-08-18

Technologies: Oracle Hyperion Data Relationship Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Data Relationship Management is an enterprise data management and integration platform used to consolidate and govern critical business information across organizations. An unauthenticated network attacker can exploit an access control vulnerability to completely compromise the system, potentially leading to unauthorized access to sensitive financial and operational data, data manipulation, and service disruption across dependent enterprise systems.

Technical details

An easily exploitable authentication bypass vulnerability exists in Oracle Hyperion Data Relationship Management version 11.2.25.0.000 in the access and security component. The vulnerability allows an unauthenticated attacker with network access via TCP to bypass authentication controls without requiring user interaction or additional complexity. Successful exploitation results in complete system takeover with high confidentiality, integrity, and availability impact. The scope is changed, meaning attacks on Hyperion DRM can significantly compromise additional connected products and systems. No patch information is currently available in the advisory.

Affected products

  • Oracle Hyperion Data Relationship Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats