Junglewise Threat Intelligence

CVE-2026-70888: Oracle Hyperion Data Relationship Management access control vulnerability

CVE-2026-70888 · Severity: medium · CVSS 6.6 · Published 2026-08-18

Technologies: Oracle Hyperion Data Relationship Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Data Relationship Management is a data governance and reporting tool used to manage enterprise information models. A flaw in the access control and security mechanisms allows a highly privileged attacker with network access to fully compromise the system, potentially exposing or modifying sensitive business data and disrupting critical reporting operations.

Technical details

This vulnerability in Oracle Hyperion Data Relationship Management 11.2.25.0.000 involves a flaw in the access and security controls that can be exploited by a high-privileged attacker with network access via HTTP. The vulnerability is difficult to exploit and requires high privileges, but successful exploitation results in full system compromise with impacts to confidentiality, integrity, and availability. An attacker can gain complete control of the product. The vulnerability is identified as CVE-2026-70888 and patches are available through Oracle's security updates.

Affected products

  • Oracle Hyperion Data Relationship Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats