Description
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Data Relationship Management executes to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-08-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Local attacker with low-level privileges on the server hosting Oracle Hyperion Data Relationship Management can exploit a flaw in the Access and Security component to gain unauthorized access to the system. The vulnerability allows the attacker to read data that is normally restricted to higher privileged users, with the potential to view all data exposed by the application. The breach would compromise the confidentiality of the organization’s sensitive information but does not directly lead to integrity or availability disruption.

Affected Systems

The affected product is Oracle Hyperion Data Relationship Management, version 11.2.25.0.000. Because the vulnerability includes a scope change, successful exploitation could also impact other applications or services that share the same infrastructure or data sources, extending the attack surface beyond the single product.

Risk and Exploitability

The CVSS v3.1 base score of 6.5 classifies the issue as a moderate severity flaw. Exploitation requires local logon to the infrastructure but only low privileges, with no user interaction needed. The EPSS score of < 1% indicates a very low but non‑zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an attacker who has already gained access to the host through other means, such as phishing or exploiting other local weaknesses, and then uses this flaw to harvest confidential data.

Generated by OpenCVE AI on August 21, 2026 at 03:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch for CVE-2026-70895 released by Oracle, as referenced in the official advisory
  • Limit local account privileges to the minimum necessary for each functional role, enforcing least privilege for all users who can log onto the Hyperion host
  • Monitor audit and access logs for anomalous read activity on Hyperion data records and trigger alerts for any unauthorized data access attempts

Generated by OpenCVE AI on August 21, 2026 at 03:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Title Local Credential Escalation Leading to Unauthorized Data Access in Oracle Hyperion Data Relationship Management
Weaknesses CWE-284

Wed, 19 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
Title Low-privilege Data Access in Oracle Hyperion Data Relationship Management
Weaknesses CWE-284

Wed, 19 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title Low-privilege Data Access in Oracle Hyperion Data Relationship Management
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Data Relationship Management executes to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle hyperion Data Relationship Management
CPEs cpe:2.3:a:oracle:hyperion_data_relationship_management:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Data Relationship Management
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Hyperion Data Relationship Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-22T01:56:25.128Z

Reserved: 2026-08-04T22:06:34.604Z

Link: CVE-2026-70895

cve-icon Vulnrichment

Updated: 2026-08-22T01:56:19.512Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:47.117

Modified: 2026-08-24T16:23:30.173

Link: CVE-2026-70895

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T03:45:03Z

Weaknesses