Access and Security Vulnerability in Oracle Hyperion Data Relationship Management
CVE-2026-70903

8.7HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-70903?

A security vulnerability exists in Oracle Hyperion Data Relationship Management, enabling low-privileged attackers with network access via HTTPS to perform unauthorized actions. This vulnerability can lead to the creation, deletion, or modification of critical data, significantly impacting the integrity and confidentiality of the system. Successful exploitation requires human interaction from an external user, and the implications may extend beyond the affected Oracle product, potentially affecting other connected systems.

Affected Version(s)

Oracle Hyperion Data Relationship Management 11.2.25.0.000

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.