CVE-2026-70880

10.0

Oracle · Oracle Hyperion Data Relationship Management

A critical vulnerability in Oracle Hyperion Data Relationship Management allows an unauthenticated remote attacker to gain complete system control via TCP.

Executive summary

This critical vulnerability permits unauthenticated attackers to fully compromise the Oracle Hyperion Data Relationship Management application, threatening the integrity of master data.

Vulnerability

This vulnerability resides in the access and security component of the software and is easily exploitable by an unauthenticated attacker with network access. The flaw allows for a total takeover of the application and carries the potential for scope change impacting connected systems.

Business impact

As this component manages master data, a successful compromise could lead to the unauthorized modification or destruction of critical business data, leading to severe operational and financial consequences. With a CVSS score of 10.0, this vulnerability is classified as critical, requiring urgent attention to prevent unauthorized access to sensitive corporate records.

Remediation

Immediate Action: Update the Oracle Hyperion Data Relationship Management installation to the latest version as specified in the August 2026 Oracle security advisory.

Proactive Monitoring: Monitor system logs for unauthorized authentication attempts or unusual TCP traffic directed toward the application's security management ports.

Compensating Controls: Implement strict network access control lists to ensure the application is not accessible from untrusted networks or the public internet.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this vulnerability, combined with the lack of authentication required for exploitation, demands immediate remedial action. Administrators should verify their current version and apply the appropriate security updates provided by Oracle without delay.

More Oracle CVEs