Junglewise Threat Intelligence

CVE-2026-70904: Oracle Hyperion Data Relationship Management unauthorized access in access and security

CVE-2026-70904 · Severity: high · CVSS 8.1 · Published 2026-08-18

Technologies: Oracle Hyperion Data Relationship Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Data Relationship Management is a financial planning and analysis tool used by enterprises to manage complex data relationships. An unauthenticated attacker with physical access to the network segment can bypass security controls to create, delete, or modify critical financial data, or gain complete access to sensitive information stored in the system.

Technical details

This vulnerability in the access and security component of Oracle Hyperion Data Relationship Management allows an unauthenticated attacker with adjacent network access (physical communication segment attached to the hardware) to compromise the system through an easily exploitable attack vector. The vulnerability results in unauthorized creation, deletion, modification, and access to critical data within the application. No user interaction or authentication is required to exploit this issue. The attack affects version 11.2.25.0.000, with impacts to both confidentiality and integrity of data.

Affected products

  • Oracle Hyperion Data Relationship Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats