Description
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-08-18
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability stems from a failure in the access control mechanisms within the Oracle Hyperion Data Relationship Management component. An attacker with low privileges and network access via HTTP can exploit this flaw to bypass authorization checks, enabling unauthorized creation, deletion, or modification of critical data and user permissions. The resulting changes compromise data confidentiality and integrity without providing remote code execution capabilities.

Affected Systems

Oracle Hyperion Data Relationship Management version 11.2.25.0.000 is affected. No other product versions are listed as impacted, though the scope of the vulnerability may extend to other related Oracle Hyperion products.

Risk and Exploitability

The CVSS 3.1 Base Score of 8.2 indicates a high severity vulnerability with significant confidentiality and integrity impacts. Exploitation does not require special privileges beyond low-level access and is reachable through standard HTTP traffic. The EPSS score is < 1%, indicating a very low probability of exploitation, although the vulnerability is not listed in CISA’s KEV catalog, so no widespread active exploitation is known. Attackers would need to identify and connect to the Oracle Hyperion Data Relationship Management web interface from a network that can reach it.

Generated by OpenCVE AI on August 22, 2026 at 05:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Hyperion Data Relationship Management patch or update to a fixed version.
  • Restrict HTTP access to the application by limiting connections to trusted networks or IP ranges, and consider using a VPN or firewall rules.
  • Enforce strict role‑based access controls and regularly audit permission changes and data access logs.

Generated by OpenCVE AI on August 22, 2026 at 05:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Access Control Bypass Enables Unauthorized Data Manipulation in Oracle Hyperion Data Relationship Management

Sat, 22 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Manipulation via Improper Authorization in Oracle Hyperion Data Relationship Management
Weaknesses CWE-285

Sat, 22 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Manipulation via Improper Authorization in Oracle Hyperion Data Relationship Management
Weaknesses CWE-285

Thu, 20 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Manipulation via Improper Access Control in Oracle Hyperion Data Relationship Management
Weaknesses CWE-284

Wed, 19 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Manipulation via Improper Access Control in Oracle Hyperion Data Relationship Management
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle hyperion Data Relationship Management
CPEs cpe:2.3:a:oracle:hyperion_data_relationship_management:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Data Relationship Management
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Hyperion Data Relationship Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-22T01:51:26.761Z

Reserved: 2026-08-04T22:06:34.604Z

Link: CVE-2026-70892

cve-icon Vulnrichment

Updated: 2026-08-22T01:51:13.393Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:45.940

Modified: 2026-08-24T16:39:51.513

Link: CVE-2026-70892

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T05:45:05Z

Weaknesses