Junglewise Threat Intelligence

CVE-2026-70901: Oracle Hyperion Data Relationship Management CSRF in access and security

CVE-2026-70901 · Severity: high · CVSS 8.1 · Published 2026-08-18

Technologies: Oracle Hyperion Data Relationship Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Data Relationship Management is an enterprise data governance and management tool used by organizations to maintain data quality and integrity. An unauthenticated attacker can exploit a vulnerability via HTTP to perform unauthorized creation, deletion, or modification of critical business data without authentication, requiring only that a legitimate user interact with a malicious link or page. This can result in unauthorized access to and modification of sensitive data across the entire system.

Technical details

This is an easily exploitable vulnerability in the access and security component of Oracle Hyperion Data Relationship Management 11.2.25.0.000. The vulnerability is network-reachable via HTTP and does not require prior authentication; however, exploitation requires user interaction (UI:R), suggesting a CSRF or social engineering vector. An unauthenticated attacker can achieve unauthorized creation, deletion, or modification of critical data and complete read access to all accessible data. The CVSS 3.1 score of 8.1 reflects high confidentiality and integrity impacts with no availability impact. Patch status and remediation details should be obtained from Oracle's security advisory.

Affected products

  • Oracle Hyperion Data Relationship Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats