Junglewise Threat Intelligence

CVE-2026-70903: Oracle Hyperion Data Relationship Management cross-site request forgery in Access and security

CVE-2026-70903 · Severity: high · CVSS 8.7 · Published 2026-08-18

Technologies: Oracle Hyperion Data Relationship Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Data Relationship Management is an enterprise data management system used to store and manage critical business information. This vulnerability allows a low-privileged attacker to manipulate a legitimate user (via social engineering or phishing) to perform unauthorized actions, potentially resulting in unauthorized creation, deletion, or modification of sensitive data within the system. The impact extends beyond the vulnerable product to other systems connected to or dependent on Hyperion data.

Technical details

This is a cross-site request forgery (CSRF) or similar user-interaction-based vulnerability affecting the Access and security component of Oracle Hyperion Data Relationship Management version 11.2.25.0.000. The vulnerability is easily exploitable over HTTPS by a low-privileged attacker and requires user interaction (a legitimate user must be socially engineered or follow a malicious link while authenticated). Successful exploitation allows unauthorized read, create, modify, or delete operations on critical data accessible to the targeted user account, with potential scope change affecting downstream systems. The CVSS 3.1 score of 8.7 reflects high confidentiality and integrity impact with no availability impact (AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N). Patch or update availability should be checked via Oracle's Critical Patch Update (CPU) advisories.

Affected products

  • Oracle Hyperion Data Relationship Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats