Description
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the Access and security component of Oracle Hyperion Data Relationship Management permits a low-privileged attacker who can reach the application over HTTP to compromise the system. The flaw is easily exploitable and can lead to full system takeover, affecting confidentiality, integrity and availability.

Affected Systems

Vulnerable version is Oracle Hyperion Data Relationship Management 11.2.25.0.000, distributed by Oracle Corporation. No other versions were listed as affected.

Risk and Exploitability

The CVSS base score of 8.8 and an EPSS score of less than 1% do not mean exploitation is unlikely; the flaw is actively exploitable over standard HTTP without authentication. Because it grants a low-privileged attacker the ability to gain full control, the risk is considered high. The vulnerability is not listed in the CISA KEV catalog, so no known public exploits are recorded yet, but the attack scenario requires only network access to the vulnerable port and no special credentials, implying a straightforward exploitation path.

Generated by OpenCVE AI on August 21, 2026 at 06:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security patch or upgrade to a non-affected version of Oracle Hyperion Data Relationship Management 11.2.25.0.000.
  • Restrict network access to the Hyperion instance to internal or VPN-only connections, preventing exposure to general internet-facing traffic.
  • Review and tighten role‑based access controls, ensuring that low‑privileged users do not have rights to access or modify management interfaces.

Generated by OpenCVE AI on August 21, 2026 at 06:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege Attack Enables Full System Takeover in Oracle Hyperion Data Relationship Management
Weaknesses CWE-284
CWE-287

Fri, 21 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Title HTTP Access Exploit Enables Full System Takeover in Oracle Hyperion Data Relationship Management
Weaknesses CWE-284

Wed, 19 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Title HTTP Access Exploit Enables Full System Takeover in Oracle Hyperion Data Relationship Management
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle hyperion Data Relationship Management
CPEs cpe:2.3:a:oracle:hyperion_data_relationship_management:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Data Relationship Management
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Hyperion Data Relationship Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-21T12:10:31.731Z

Reserved: 2026-08-04T22:06:34.603Z

Link: CVE-2026-70886

cve-icon Vulnrichment

Updated: 2026-08-21T12:10:18.256Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:45.207

Modified: 2026-08-21T15:59:55.943

Link: CVE-2026-70886

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T06:30:10Z

Weaknesses