Access and Security Vulnerability in Oracle Hyperion Data Relationship Management
CVE-2026-70899

8.8HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-70899?

A vulnerability has been identified within Oracle Hyperion Data Relationship Management that allows a low privileged attacker with network access through HTTP to gain unauthorized control over the application. This poses significant risks as successful exploitation can lead to a complete takeover of the affected system. The vulnerability affects supported version 11.2.25.0.000 and impacts the confidentiality, integrity, and availability of the product, marking a critical need for attention and remediation.

Affected Version(s)

Oracle Hyperion Data Relationship Management 11.2.25.0.000

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.