Junglewise Threat Intelligence

CVE-2026-70887: Oracle Hyperion Data Relationship Management unauthorized access in HTTP

CVE-2026-70887 · Severity: high · CVSS 8.2 · Published 2026-08-18

Technologies: Oracle Hyperion Data Relationship Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Data Relationship Management is an enterprise application used for managing complex data relationships and hierarchies in large organizations. An unauthenticated attacker with network access can exploit an HTTP vulnerability to gain unauthorized access to sensitive data, modify or delete information, and potentially compromise the integrity of critical business data without any credentials or special access.

Technical details

This is an easily exploitable vulnerability in the HTTP access layer of Oracle Hyperion Data Relationship Management that requires no authentication or user interaction. An unauthenticated attacker with network access can send specially crafted HTTP requests to bypass access controls and security mechanisms. The vulnerability allows attackers to read confidential data, insert, update, or delete information from the application. The attack vector is network-based with no complexity requirements, making it trivial to exploit. Patches should be available through Oracle's Critical Patch Updates.

Affected products

  • Oracle Hyperion Data Relationship Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats