Junglewise Threat Intelligence

CVE-2026-70893: Oracle Hyperion Data Relationship Management SQL injection in access control

CVE-2026-70893 · Severity: high · CVSS 8.2 · Published 2026-08-18

Technologies: Oracle Hyperion Data Relationship Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Data Relationship Management is an enterprise data modeling and relationship platform used to manage critical business data hierarchies and metadata. A SQL injection vulnerability in the access control component allows authenticated attackers to read, modify, or delete sensitive data across the application, potentially affecting multiple connected systems and causing significant data loss or unauthorized disclosure.

Technical details

This is a SQL injection vulnerability in the access and security component of Oracle Hyperion Data Relationship Management version 11.2.25.0.000. The vulnerability requires network access and low-level user privileges, with high attack complexity. An authenticated attacker can inject malicious SQL to bypass access controls, leading to unauthorized creation, deletion, or modification of critical data and complete unauthorized access to all accessible data. The scope is marked as changed, indicating potential impact to other connected products and systems. A patch is available via Oracle's critical security update.

Affected products

  • Oracle Hyperion Data Relationship Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats