Sceawere

Vulnerability Detail

CVE-2026-70879UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion Data Relationship Management Privilege Escalation Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.8
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Data Relationship Management
Attack Type
Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Data Relationship Management executes to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Data Relationship Management.
Vector String
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Data Relationship Management executes to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.8",
  "pubDate": "2026-08-18T21:17:44.370Z",
  "pubdate": "2026-08-18T21:17:44.370Z",
  "executiveSummary": "A security vulnerability has been identified within the Oracle Hyperion Data Relationship Management product of Oracle Hyperion, specifically residing in the Access and security component. The vulnerability affects the supported version 11.2.25.0.000 and is classified as a difficult to exploit flaw that can lead to a complete system compromise.\nThe risk implications are severe due to the potential for a scope change, meaning that successful exploitation of this vulnerability within Oracle Hyperion Data Relationship Management can also significantly impact additional associated products. An attacker achieving successful exploitation can attain a complete takeover of the affected product, resulting in total loss of confidentiality, integrity, and availability.\nRegarding attacker capabilities and exploitation requirements, the attack vector is local (AV:L), meaning the adversary must have prior logon access to the underlying infrastructure where Oracle Hyperion Data Relationship Management executes. The attack complexity is rated as high (AC:H), and the required privileges are low (PR:L). Furthermore, user interaction is not required (UI:N) for the attack to succeed.\nGiven the CVSS 3.1 Base Score of 7.8 with high impacts across Confidentiality, Integrity, and Availability (C:H/I:H/A:H), organizations utilizing the affected version must prioritize defensive measures to restrict unauthorized local access and monitor for privilege escalation attempts targeting the Access and security component.",
  "technicalDetails": "The vulnerability resides in the Access and security component of Oracle Hyperion Data Relationship Management version 11.2.25.0.000. The root cause stems from insecure access controls or flawed authorization logic within the local execution environment, allowing a locally authenticated user to manipulate security boundaries.\nThe exploitation method requires the adversary to possess low-privileged logon access to the host infrastructure hosting the Oracle Hyperion Data Relationship Management application. Due to the high attack complexity (AC:H), the attacker must execute precise procedural steps to leverage misconfigurations or internal trust relationships within the Access and security component.\nThe attack flow proceeds as follows: First, the low-privileged attacker establishes an interactive or programmatic session on the infrastructure where Oracle Hyperion Data Relationship Management executes. Second, leveraging the local privileges and exploiting the high-complexity flaw within the Access and security component, the adversary interacts with internal application binaries, configuration files, or runtime execution contexts. Third, the attacker bypasses intended authorization controls, escalating privileges within the application context.\nBecause the vulnerability exhibits a scope change (S:C), the compromise is not strictly contained within the boundaries of Oracle Hyperion Data Relationship Management. Successful exploitation breaches the security context of the primary application and propagates to impact additional integrated products residing within the infrastructure ecosystem.\nPost-exploitation impact culminates in a complete takeover of Oracle Hyperion Data Relationship Management. The attacker achieves unrestricted administrative control over the application, enabling them to read, modify, or delete sensitive master data structures, compromise system integrity, and disrupt availability services across dependent workflows."
}
CVE-2026-70879: Oracle Hyperion Data Relationship Management Privilege Escalation Vulnerability (HIGH Severity, CVSS: 7.8) - Sceawere