Access and Security Vulnerability in Oracle Hyperion Data Relationship Management
CVE-2026-70887

8.2HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-70887?

A significant access control vulnerability has been identified in Oracle Hyperion Data Relationship Management, specifically within its access and security components. The affected version, 11.2.25.0.000, can be exploited by unauthenticated attackers with network access via HTTP. This vulnerability poses a serious risk, potentially allowing attackers to gain unauthorized access to critical data or compromise the integrity of all accessible data within the Oracle Hyperion environment. Successful exploitation may lead to unauthorized updates, inserts, or deletions of data, highlighting the need for immediate attention and remediation.

Affected Version(s)

Oracle Hyperion Data Relationship Management 11.2.25.0.000

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.