Junglewise Threat Intelligence

CVE-2026-70889: Oracle Hyperion Data Relationship Management authentication bypass in access and security

CVE-2026-70889 · Severity: high · CVSS 7.5 · Published 2026-08-18

Technologies: Oracle Hyperion Data Relationship Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Data Relationship Management is a data integration and management platform used to consolidate and manage enterprise financial and operational data. An unauthenticated remote attacker can bypass access controls via the HTTP interface to read all sensitive data stored in the system, potentially exposing critical business intelligence, financial records, and other confidential information without authorization.

Technical details

This is an authentication bypass vulnerability in the access and security component of Oracle Hyperion Data Relationship Management. The vulnerability allows unauthenticated attackers to access the system remotely over HTTP with no user interaction required. The flaw enables complete unauthorized disclosure of confidential data within the application, affecting version 11.2.25.0.000. The vulnerability has a CVSS 3.1 score of 7.5 (high severity) with attack vector network, low complexity, and no privilege requirements. No patch information is publicly available in the provided advisory, though Oracle's critical patch updates typically address such issues.

Affected products

  • Oracle Hyperion Data Relationship Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats