Description
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).
Published: 2026-08-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the access and security component of Oracle Hyperion Data Relationship Management allows an attacker who can reach the system over HTTP to create, delete, or alter critical data without authentication. The vulnerability results in significant confidentiality and integrity breaches, permitting unauthorized users to modify or read sensitive information. The weakness is rooted in improper access control wherein the system fails to verify the identity of requesting users before processing critical actions.

Affected Systems

The only affected product is Oracle Hyperion Data Relationship Management, version 11.2.25.0.000, as identified by Oracle’s CNA. The vulnerability exists in all installations of that specific release and is not known to affect other versions or similar products.

Risk and Exploitability

The CVSS 3.1 score of 8.1 indicates substantial impact on confidentiality and integrity, while the attack vector is network-based via HTTP. Successful exploitation requires an unauthenticated attacker with network access and human interaction from a user other than the attacker, such as a phishing or social‑engineering step. The EPSS score of less than 1% indicates a low probability of exploitation, yet combined with the CVSS score the vulnerability remains a high‑priority issue. The advisory is not listed in the CISA KEV catalog, suggesting the attack is not yet widely observed but remains a significant concern.

Generated by OpenCVE AI on August 21, 2026 at 03:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and apply Oracle’s latest security patch for Hyperion Data Relationship Management, targeting a version newer than 11.2.25.0.000.
  • Restrict HTTP access to the Hyperion server to trusted IP ranges or enforce VPN requirements to limit exposure to the broader network.
  • Implement additional authentication controls (e.g., LDAP, SAML) and enforce strict role‑based access to prevent unauthorized modification of data.

Generated by OpenCVE AI on August 21, 2026 at 03:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 20 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Unauthorized Data Modification in Oracle Hyperion Data Relationship Management
Weaknesses CWE-284

Wed, 19 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Unauthorized Data Modification in Oracle Hyperion Data Relationship Management
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle hyperion Data Relationship Management
CPEs cpe:2.3:a:oracle:hyperion_data_relationship_management:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Data Relationship Management
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Hyperion Data Relationship Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-22T02:07:13.102Z

Reserved: 2026-08-04T22:06:34.604Z

Link: CVE-2026-70901

cve-icon Vulnrichment

Updated: 2026-08-22T02:07:05.845Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:47.820

Modified: 2026-08-24T16:46:46.120

Link: CVE-2026-70901

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T03:45:03Z

Weaknesses