Description
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability in the Access and Security component of Oracle Hyperion Data Relationship Management version 11.2.25.0.000 allows a low‑privileged attacker who can reach the application over HTTP to compromise the system. Although the flaw is difficult to exploit, successful exploitation grants full control of the application, enabling the attacker to read, modify, or delete data and to take over the service. The resulting impact spans confidentiality, integrity, and availability, given that the system holds sensitive organizational information.

Affected Systems

Only Oracle Hyperion Data Relationship Management version 11.2.25.0.000 is listed as affected. The vendor is Oracle Corporation. The advisory notes a scope change that could affect additional products if those products are integrated with the compromised instance.

Risk and Exploitability

The vulnerability’s CVSS v3.1 base score is 8.5, indicating a high severity risk. The EPSS score is reported as less than 1%, indicating a very low probability of exploitation, and the CVE is not listed in the CISA KEV catalog, implying no known public exploits yet. The attack vector is network‑based; an attacker needs only HTTP access and low privileges, making the attack surface sizable. Because the flaw changes the scope, a successful attack may also impact other products that interact with the compromised Hyperion deployment.

Generated by OpenCVE AI on August 21, 2026 at 06:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the security update or patch released by Oracle for version 11.2.25.0.000
  • Restrict HTTP access to the Hyperion service to trusted IP addresses or VPN tunnels only
  • Disable or remove any unused HTTP endpoints that expose configuration or administrative functions to reduce the attack surface

Generated by OpenCVE AI on August 21, 2026 at 06:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Access Compromise Allows Full Control over Oracle Hyperion Data Relationship Management
Weaknesses CWE-284

Fri, 21 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Remote Takeover via HTTP in Oracle Hyperion Data Relationship Management
Weaknesses CWE-284
CWE-285

Wed, 19 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Title Remote Takeover via HTTP in Oracle Hyperion Data Relationship Management
Weaknesses CWE-284
CWE-285

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle hyperion Data Relationship Management
CPEs cpe:2.3:a:oracle:hyperion_data_relationship_management:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Data Relationship Management
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Hyperion Data Relationship Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-24T15:19:42.100Z

Reserved: 2026-08-04T22:06:34.603Z

Link: CVE-2026-70885

cve-icon Vulnrichment

Updated: 2026-08-24T15:12:24.991Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:45.090

Modified: 2026-08-24T17:40:37.697

Link: CVE-2026-70885

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T06:30:10Z

Weaknesses