Junglewise Threat Intelligence

CVE-2026-70899: Oracle Hyperion Data Relationship Management privilege escalation in access control

CVE-2026-70899 · Severity: high · CVSS 8.8 · Published 2026-08-18

Technologies: Oracle Hyperion Data Relationship Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Data Relationship Management is a data management platform used by enterprises to organize and maintain large-scale financial and operational datasets. A flaw in the access control component allows a low-privileged network user to completely compromise the system without requiring additional interaction, leading to unauthorized access to sensitive data and potential system takeover.

Technical details

The vulnerability is an authentication or authorization bypass in the access control component of Oracle Hyperion Data Relationship Management. It affects version 11.2.25.0.000 and can be exploited by a low-privileged attacker with network access via HTTP. The attack requires authentication but does not require user interaction or elevated privileges to trigger. Successful exploitation results in complete compromise of the system with high impact to confidentiality, integrity, and availability. No public exploit information indicates active wild exploitation at this time; patch availability from Oracle should be verified through their security bulletins.

Affected products

  • Oracle Hyperion Data Relationship Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats