Description
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-08-18
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle Hyperion Data Relationship Management allows an unauthenticated attacker with network access via HTTP to create, modify, or delete critical data objects and to gain reading access to all data. This flaw stems from improper access control within the Access and Security component, enabling attackers to bypass authentication and perform privileged actions. It is an example of Improper Access Control (CWE‑284), leading to severe impacts on confidentiality and integrity.

Affected Systems

Oracle Corporation’s Hyperion Data Relationship Management, version 11.2.25.0.000, is the affected product. No other versions are reported as vulnerable, which is inferred from the available data.

Risk and Exploitability

The risk is high, reflected by the CVSS score of 9.1. The EPSS score of < 1% indicates a very low, but nonzero, likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw over HTTP without authentication, indicating a likely network or internet attack vector. External references point to an Oracle security advisory detailing a patch for this version.

Generated by OpenCVE AI on August 24, 2026 at 22:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch or update to a version of Hyperion Data Relationship Management that includes the fix referenced in the Oracle security advisory (CSPU Aug 2026).
  • Restrict HTTP access to the Hyperion server by configuring firewall rules or IP allowlists to permit only trusted network segments or IP addresses.
  • Verify that authentication and session management are enforced for all user interfaces; ensure that no unauthenticated endpoints remain exposed.

Generated by OpenCVE AI on August 24, 2026 at 22:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Control Vulnerability in Oracle Hyperion Data Relationship Management 11.2.25.0.000

Mon, 24 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Data Creation, Modification, and Deletion in Oracle Hyperion Data Relationship Management
Weaknesses CWE-285
CWE-287

Mon, 24 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Data Creation, Modification, and Deletion in Oracle Hyperion Data Relationship Management
Weaknesses CWE-285
CWE-287

Fri, 21 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Attack Allows Data Alteration in Oracle Hyperion Data Relationship Management
Weaknesses CWE-284

Wed, 19 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Attack Allows Data Alteration in Oracle Hyperion Data Relationship Management
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle hyperion Data Relationship Management
CPEs cpe:2.3:a:oracle:hyperion_data_relationship_management:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Data Relationship Management
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Hyperion Data Relationship Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T03:56:32.353Z

Reserved: 2026-08-04T22:06:34.602Z

Link: CVE-2026-70872

cve-icon Vulnrichment

Updated: 2026-08-24T14:49:52.116Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:43.487

Modified: 2026-08-25T04:18:18.607

Link: CVE-2026-70872

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T22:45:03Z

Weaknesses