Junglewise Threat Intelligence

CVE-2026-70894: Oracle Hyperion Data Relationship Management privilege escalation in access controls

CVE-2026-70894 · Severity: high · CVSS 7.7 · Published 2026-08-18

Technologies: Oracle Hyperion Data Relationship Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Data Relationship Management is a financial and operational data management system used by enterprises to consolidate and manage complex business data. A vulnerability in its access controls allows a user with local system access to the server to bypass authentication and gain full read and write access to all sensitive business data managed by the system, potentially compromising financial records, consolidations, and other critical reporting data.

Technical details

This is a local privilege escalation vulnerability in the access and security component of Oracle Hyperion Data Relationship Management version 11.2.25.0.000. The vulnerability is easily exploitable and requires only local logon access to the infrastructure (no network access required). An unauthenticated attacker with local system access can bypass authentication controls and achieve unauthorized creation, deletion, or modification of critical data, as well as complete read access to all data managed by the application. The CVSS 3.1 score of 7.7 reflects high confidentiality and integrity impacts. No patches or fixes are explicitly mentioned in available reference material.

Affected products

  • Oracle Hyperion Data Relationship Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats