Access and Security Vulnerability in Oracle Hyperion Data Relationship Management
CVE-2026-70892

8.2HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-70892?

A vulnerability has been identified in Oracle Hyperion Data Relationship Management that could potentially allow low-privileged attackers with network access via HTTP to compromise the system. Although specifically related to the Access and Security component, the implications may extend beyond this product, allowing unauthorized creation, deletion, or modification of critical data. Successful exploitation could lead to significant data breaches, impacting the confidentiality and integrity of accessible information within the system.

Affected Version(s)

Oracle Hyperion Data Relationship Management 11.2.25.0.000

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.