Junglewise Threat Intelligence

CVE-2026-70882: Oracle Hyperion Data Relationship Management CSRF in access controls

CVE-2026-70882 · Severity: high · CVSS 8.7 · Published 2026-08-18

Technologies: Oracle Hyperion Data Relationship Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Data Relationship Management is an enterprise data governance platform used to manage business rules and relationships across financial and operational systems. A CSRF vulnerability in access controls allows an attacker with low-level network access to trick authenticated users into performing unauthorized actions, potentially enabling attackers to create, delete, or modify critical business data and access sensitive information across the system.

Technical details

This vulnerability is a cross-site request forgery (CSRF) affecting the access and security controls in Oracle Hyperion Data Relationship Management. The vulnerability is network-accessible via HTTP and can be exploited by a low-privileged attacker, but requires user interaction (social engineering or phishing) from a legitimate user to succeed. Successful exploitation allows unauthorized modification, creation, or deletion of critical data, as well as unauthorized access to all accessible data within the product. The scope is marked as "changed," meaning the impact extends beyond Data Relationship Management to other Oracle Hyperion products. Version 11.2.25.0.000 is confirmed affected; patch availability should be verified through Oracle's official security advisory.

Affected products

  • Oracle Hyperion Data Relationship Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats