CVE-2026-70874

8.8

Oracle · Hyperion Data Relationship Management

A security vulnerability in Oracle Hyperion Data Relationship Management allows a low-privileged network attacker to perform a complete system takeover.

Executive summary

This high-severity vulnerability in Oracle Hyperion Data Relationship Management permits unauthorized remote attackers with low-level access to compromise the system.

Vulnerability

This is an easily exploitable vulnerability within the access and security component of the product. It allows a low-privileged attacker with HTTP network access to bypass security controls, ultimately resulting in a full takeover of the Oracle Hyperion Data Relationship Management software.

Business impact

The vulnerability is rated with a CVSS score of 8.8, reflecting the high risk to data integrity and system availability. Since this component often manages critical master data, a compromise could lead to widespread data corruption, unauthorized modification of sensitive business relationships, and significant downtime for business intelligence operations.

Remediation

Immediate Action: Review the August 2026 Oracle Security Alert and apply the vendor-provided updates immediately upon availability.

Proactive Monitoring: Monitor HTTP traffic for suspicious queries or unauthorized access attempts against the Data Relationship Management console and review logs for privilege escalation indicators.

Compensating Controls: Implement network-level access controls to ensure the application is not accessible from untrusted networks and utilize a WAF to inspect incoming HTTP requests for malicious payloads.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical nature of the data managed by this product, security teams should treat this vulnerability with high urgency. Patching the affected environment is the only way to effectively mitigate the risk of a total system compromise.

More Oracle CVEs