Junglewise Threat Intelligence

CVE-2026-70900: Oracle Hyperion Data Relationship Management authentication bypass in access control

CVE-2026-70900 · Severity: high · CVSS 8.7 · Published 2026-08-18

Technologies: Oracle Hyperion Data Relationship Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Data Relationship Management is a data management and reporting product used by enterprises to model and manage complex business data relationships. An unauthenticated attacker can bypass security controls over the network to read, create, modify, or delete critical business data and configuration information without authorization, potentially affecting downstream business intelligence and operational systems.

Technical details

This is an authentication bypass or authorization flaw in the access control component of Oracle Hyperion Data Relationship Management affecting version 11.2.25.0.000. The vulnerability is accessible to unauthenticated attackers via HTTP (network-reachable), though it is difficult to exploit, suggesting non-trivial preconditions or complexity. Successful exploitation results in unauthorized access to create, modify, delete, or read critical data—indicating both integrity and confidentiality impacts across the product. The scope change designation suggests potential lateral impact to connected systems. No patch availability information is currently provided in the advisory.

Affected products

  • Oracle Hyperion Data Relationship Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats