Sceawere

Vulnerability Detail

CVE-2026-70892UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion DRM Security Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.2
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Data Relationship Management
Attack Type
Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data.
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.2",
  "pubDate": "2026-08-18T21:17:45.940Z",
  "pubdate": "2026-08-18T21:17:45.940Z",
  "executiveSummary": "A security vulnerability has been identified within the Access and Security component of the Oracle Hyperion Data Relationship Management product, specifically affecting version 11.2.25.0.000. This vulnerability presents a significant risk to organizational data integrity and confidentiality due to its potential for unauthorized data manipulation and exposure. Although categorized as difficult to exploit, a successfully executed attack can be initiated by a low-privileged threat actor with network access over the HTTP protocol. The nature of the flaw involves a scope change, meaning that successful exploitation is not strictly limited to the primary application domain but can also significantly impact additional integrated or associated products within the enterprise architecture.\nThe primary risk implications center on the compromise of critical enterprise master data assets managed within the Oracle Hyperion Data Relationship Management ecosystem. Successful exploitation grants the adversary unauthorized capabilities to perform creation, deletion, and modification actions against critical data or all accessible data repositories within the system. Furthermore, the attacker gains unauthorized read access to critical data or complete access to all data accessible by the application. Given the CVSS 3.1 Base Score of 8.2 with high confidentiality and integrity impacts, organizations utilizing the affected version must prioritize defensive measures. The combination of network accessibility, low privilege requirements, and cross-product scope changes necessitates rigorous monitoring and prompt remediation planning to counteract potential exploitation vectors.",
  "technicalDetails": "The vulnerability resides within the Access and Security component of Oracle Hyperion Data Relationship Management version 11.2.25.0.000. This component is responsible for enforcing authorization boundaries, managing user privileges, and securing access to master data hierarchies and operational functions. The root cause stems from flaws in how access controls and security parameters are validated or enforced during HTTP request processing, allowing an authenticated user with low privileges to bypass intended authorization checks under specific conditions.\nExploitation of this vulnerability requires the attacker to possess low-level valid user credentials and network access to the application via the HTTP protocol. Because the CVSS attack complexity is rated as high, successful exploitation typically demands precise timing, specific environmental conditions, or non-trivial manipulation of request parameters to induce the authorization bypass. The attack flow begins with the adversary crafting malicious HTTP requests designed to interact with vulnerable endpoints within the Access and Security component. Despite the low privilege level of the attacker's session, the flaw permits the execution of unauthorized operations that transcend the intended security context.\nDue to the scope change (S:C) characteristic of this vulnerability, the impact extends beyond the immediate boundaries of Oracle Hyperion Data Relationship Management. When the application interacts with external or underlying systems, the compromised security context can propagate, leading to unauthorized data access or modification in secondary products integrated within the infrastructure. Post-exploitation impacts are severe, encompassing full confidentiality and integrity breaches. The adversary can execute unauthorized creation, deletion, and modification of critical data records, as well as harvest sensitive information across all accessible data repositories within the affected system. The attack vector relies entirely on network interactions, requiring no physical access or user interaction (UI:N), which increases the potential surface for remote exploitation by malicious insiders or compromised low-privileged accounts."
}
CVE-2026-70892: Oracle Hyperion DRM Security Vulnerability (HIGH Severity, CVSS: 8.2) - Sceawere