Description
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in the Access and security component of Oracle Hyperion Data Relationship Management. A user with only local or network‑bound privileges can exploit the vulnerability through standard HTTP traffic. Successful exploitation allows the attacker to fully compromise the application, leading to a complete takeover of confidentiality, integrity and availability. The weakness is a classic access control failure.

Affected Systems

Oracle Corporation’s Hyperion Data Relationship Management version 11.2.25.0.000 is the single affected product; no other versions or components are listed as vulnerable.

Risk and Exploitability

The CVSS 3.1 base score of 8.8 indicates a severe risk, while the EPSS score of < 1% suggests that exploit activity is currently uncommon. The vulnerability is not listed in the CISA KEV catalog. Attackers can reach the affected component over HTTP with only a low privilege account, making the flaw attractive for adversaries who can expand the compromise to full system takeover once inside the application.

Generated by OpenCVE AI on August 21, 2026 at 06:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify whether your deployment runs version 11.2.25.0.000 of Oracle Hyperion Data Relationship Management and inspect vendor advisories for available patches; apply any new patch as soon as it is released.
  • Restrict HTTP access to the Hyperion web interface to trusted networks or VPNs and enforce strict role‑based access controls to limit exposure to low‑privileged users.
  • Enable comprehensive logging and monitoring of authentication and access events to detect and block anomalous activities that could indicate exploitation of the access control flaw.

Generated by OpenCVE AI on August 21, 2026 at 06:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 07:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploit Enables Full Takeover of Oracle Hyperion Data Relationship Management
Weaknesses CWE-284

Fri, 21 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Low-Privileged Network Attack Compromises Oracle Hyperion Data Relationship Management
Weaknesses CWE-284

Wed, 19 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Title Low-Privileged Network Attack Compromises Oracle Hyperion Data Relationship Management
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle hyperion Data Relationship Management
CPEs cpe:2.3:a:oracle:hyperion_data_relationship_management:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Data Relationship Management
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Hyperion Data Relationship Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-24T15:20:26.270Z

Reserved: 2026-08-04T22:06:34.603Z

Link: CVE-2026-70877

cve-icon Vulnrichment

Updated: 2026-08-24T15:12:30.507Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:44.117

Modified: 2026-08-24T17:24:45.520

Link: CVE-2026-70877

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T07:00:12Z

Weaknesses