Executive brief
Oracle Hyperion Data Relationship Management is a data governance and reporting tool used to manage enterprise information models. A flaw in the access control and security mechanisms allows a highly privileged attacker with network access to fully compromise the system, potentially exposing or modifying sensitive business data and disrupting critical reporting operations.
Technical details
This vulnerability in Oracle Hyperion Data Relationship Management 11.2.25.0.000 involves a flaw in the access and security controls that can be exploited by a high-privileged attacker with network access via HTTP. The vulnerability is difficult to exploit and requires high privileges, but successful exploitation results in full system compromise with impacts to confidentiality, integrity, and availability. An attacker can gain complete control of the product. The vulnerability is identified as CVE-2026-70888 and patches are available through Oracle's security updates.
Affected products
- Oracle Hyperion Data Relationship Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed