Unauthorized Access Vulnerability in Oracle Hyperion Data Relationship Management
CVE-2026-70888

6.6MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-70888?

A security vulnerability has been identified in Oracle Hyperion Data Relationship Management, specifically in the access and security component. This vulnerability permits a high privileged attacker with network access via HTTP to exploit the system, potentially leading to the takeover of the application. Users of version 11.2.25.0.000 should be aware that successful exploitation may compromise the confidentiality, integrity, and availability of the data managed by Oracle Hyperion. It is crucial for users to implement recommended mitigations and updates to safeguard their systems.

Affected Version(s)

Oracle Hyperion Data Relationship Management 11.2.25.0.000

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.