Junglewise Threat Intelligence

CVE-2026-70892: Oracle Hyperion Data Relationship Management unauthorized data access in access and security component

CVE-2026-70892 · Severity: high · CVSS 8.2 · Published 2026-08-18

Technologies: Oracle Hyperion Data Relationship Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Data Relationship Management is a data governance and reporting solution used by enterprises to manage financial and operational data relationships. An authenticated network attacker can exploit a flaw in the access control mechanism to gain unauthorized access to, create, delete, or modify critical business data, potentially impacting confidentiality and integrity of sensitive information across the organization.

Technical details

This vulnerability exists in the access and security component of Oracle Hyperion Data Relationship Management version 11.2.25.0.000. It is an authorization bypass flaw that allows a low-privileged attacker with network access via HTTP to circumvent access controls. While exploitation is difficult (high complexity), an authenticated attacker can achieve unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to all accessible data in the system. The scope changes, meaning the vulnerability may impact other Oracle Hyperion products beyond DRM. A patch or security update from Oracle is required to remediate this issue.

Affected products

  • Oracle Hyperion Data Relationship Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats