Junglewise Threat Intelligence

CVE-2026-70895: Oracle Hyperion Data Relationship Management privilege escalation in access control

CVE-2026-70895 · Severity: medium · CVSS 6.5 · Published 2026-08-18

Technologies: Oracle Hyperion Data Relationship Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Data Relationship Management is an enterprise data management system used for financial consolidation and planning. A local privilege escalation vulnerability allows a low-privileged employee or operator with system access to gain unauthorized access to sensitive financial and business data, potentially impacting the confidentiality of critical organizational information across dependent systems.

Technical details

This is a privilege escalation vulnerability in the access and security component of Oracle Hyperion Data Relationship Management version 11.2.25.0.000. The vulnerability has a local attack vector (AV:L) and requires logon privileges (PR:L) but no special user interaction (UI:N). An authenticated local attacker can exploit this to bypass access controls and read sensitive data, with scope change indicating potential lateral impact to other products. The CVSS 3.1 score is 6.5, reflecting high confidentiality impact but no integrity or availability impact.

Affected products

  • Oracle Hyperion Data Relationship Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats