Junglewise Threat Intelligence

CVE-2026-70885: Oracle Hyperion Data Relationship Management access and security vulnerability

CVE-2026-70885 · Severity: high · CVSS 8.5 · Published 2026-08-18

Technologies: Oracle Hyperion Data Relationship Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Data Relationship Management is a business intelligence and financial reporting platform used by enterprises to manage complex data relationships. A security vulnerability in its access controls allows an attacker with low-level credentials and network access to fully compromise the system, potentially gaining unauthorized access to sensitive financial and operational data across the organization.

Technical details

This is a difficult-to-exploit access and security vulnerability in the access control mechanisms of Oracle Hyperion Data Relationship Management version 11.2.25.0.000. The vulnerability requires a low-privileged authenticated user with network access via HTTP and involves conditions that complicate exploitation (AC:H). A successful exploit enables an attacker to achieve complete compromise (confidentiality, integrity, and availability impacts), with scope change indicating potential for lateral movement to additional Oracle products. No patch information is provided in the advisory.

Affected products

  • Oracle Hyperion Data Relationship Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats