Junglewise Threat Intelligence

CVE-2026-70883: Oracle Hyperion Data Relationship Management unauthorized access

CVE-2026-70883 · Severity: critical · CVSS 9.1 · Published 2026-08-18

Technologies: Oracle Hyperion Data Relationship Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Data Relationship Management is a data governance platform used to manage critical business data relationships and hierarchies across enterprises. An unauthenticated attacker can exploit this vulnerability over the network to gain full read and write access to all stored data, potentially exposing sensitive information, allowing unauthorized data manipulation, or corrupting critical business records.

Technical details

This is a network-reachable authentication bypass or access control vulnerability in Oracle Hyperion Data Relationship Management 11.2.25.0.000. The vulnerability is exploitable by unauthenticated attackers via HTTP without requiring user interaction or complex preconditions. A successful exploit grants unauthorized read access (confidentiality impact) and write/delete/modify access (integrity impact) to critical data or the entire database. The attack vector is network-based with low complexity. Patch availability has not been confirmed at this time.

Affected products

  • Oracle Hyperion Data Relationship Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats