Junglewise Threat Intelligence

CVE-2026-70897: Oracle Hyperion Data Relationship Management authentication bypass

CVE-2026-70897 · Severity: high · CVSS 8.2 · Published 2026-08-18

Technologies: Oracle Hyperion Data Relationship Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Data Relationship Management is a financial planning and consolidation tool used by large enterprises to manage complex data relationships and access controls. An unauthenticated attacker on the network can bypass authentication and gain unauthorized access to sensitive financial data, modify or delete records, and potentially compromise the integrity of critical business systems without any user interaction required.

Technical details

This is an authentication bypass vulnerability in the Access and Security component of Oracle Hyperion Data Relationship Management version 11.2.25.0.000. The vulnerability allows an unauthenticated attacker with network access to communicate via HTTPS and gain unauthorized access to the application without providing valid credentials. The vulnerability requires no user interaction and no special network positioning (adjacent or local access is not required). Successful exploitation results in complete confidentiality compromise of accessible data, plus the ability to perform unauthorized modifications (insert, update, delete operations) on some accessible data. The CVSS 3.1 score of 8.2 reflects high confidentiality and limited integrity impacts with no availability impact.

Affected products

  • Oracle Hyperion Data Relationship Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats