Sceawere

Vulnerability Detail

CVE-2026-70885UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion DRM Security Compromise

Vulnerability Metadata

Severity
High
Score / CVSS
8.5
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Data Relationship Management
Attack Type
Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Data Relationship Management.
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.5",
  "pubDate": "2026-08-18T21:17:45.090Z",
  "pubdate": "2026-08-18T21:17:45.090Z",
  "executiveSummary": "An exploitable vulnerability exists within the Access and security component of the Oracle Hyperion Data Relationship Management product, specifically affecting version 11.2.25.0.000. This security flaw is categorized as difficult to exploit but presents severe risk implications due to its potential for a complete system takeover. An attacker possessing low privileges and network access via the HTTP protocol can leverage this vector to execute unauthorized operations against the target application.\nAlthough the vulnerable entry point resides entirely within Oracle Hyperion Data Relationship Management, successful exploitation introduces a scope change that enables significant secondary impacts on additional integrated or ancillary products. The severity of this vulnerability is underscored by a CVSS 3.1 Base Score of 8.5, indicating total compromise potential across the triad of confidentiality, integrity, and availability. Successful attack execution results in the complete takeover of the Oracle Hyperion Data Relationship Management environment, allowing unauthorized threat actors to manipulate sensitive master data structures, exfiltrate confidential enterprise metadata, and disrupt core business operations.",
  "technicalDetails": "The vulnerability resides within the Access and security component of Oracle Hyperion Data Relationship Management version 11.2.25.0.000. The root cause stems from insufficient validation, authorization enforcement, or improper access control handling within the security subsystem governing administrative and operational boundaries. Because the affected software exposes an interface accessible via the HTTP protocol over the network, a remote threat actor can interact directly with the vulnerable endpoints.\nExploitation requires the attacker to possess low privileges within the system and network access via HTTP, combined with high attack complexity conditions. Despite the high complexity constraint, an authenticated low-privileged user can systematically craft and transmit targeted HTTP requests designed to bypass intended security boundaries. The attack flow initiates when the malicious payload is submitted to the Access and security component, exploiting underlying logic flaws in how permissions, sessions, or access control lists are evaluated.\nUpon successful processing of the crafted payload, the exploitation mechanism triggers an elevation of privilege or unauthorized capability execution. Because the vulnerability exhibits a scope change (S:C), the impact extends beyond the immediate boundaries of Oracle Hyperion Data Relationship Management, potentially compromising interacting systems, dependent databases, or shared authentication realms linked to the enterprise deployment. The post-exploitation phase culminates in the complete takeover of the primary Oracle Hyperion Data Relationship Management application, granting the adversary unfettered administrative control over master data management workflows, user provisioning frameworks, and underlying data structures."
}
CVE-2026-70885: Oracle Hyperion DRM Security Compromise (HIGH Severity, CVSS: 8.5) - Sceawere