Junglewise Threat Intelligence

CVE-2026-70902: Oracle Hyperion Data Relationship Management privilege escalation in access control

CVE-2026-70902 · Severity: high · CVSS 7.1 · Published 2026-08-18

Technologies: Oracle Hyperion Data Relationship Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Data Relationship Management is an enterprise data management tool used to control financial and operational data relationships across organizations. A local privilege escalation vulnerability allows an authenticated user on the system to bypass access controls and gain unauthorized read/write access to sensitive corporate financial and operational data, posing a significant risk to data integrity and confidentiality.

Technical details

This vulnerability is a privilege escalation flaw in the access and security component of Oracle Hyperion Data Relationship Management version 11.2.25.0.000. The attack requires local access to the infrastructure and valid logon credentials (low-privileged user), but does not require user interaction. An authenticated attacker can exploit insufficient access control validation to create, delete, or modify critical data, or gain complete unauthorized access to all data managed by the application. The CVSS 3.1 vector (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N) indicates a local attack vector with high impact on confidentiality and integrity. Patch availability should be confirmed through Oracle's security updates.

Affected products

  • Oracle Hyperion Data Relationship Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats