6.6mediumMedium
CVE-2026-70888
Oracle Hyperion Data Relationship Management
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).
Exploitation status
- A vendor advisory or patch reference has been published.
What the metrics mean
- It is reachable over a network, without needing local access.
- For an attacker who can reach it, exploitation depends on conditions outside the attacker's control.
- To exploit it, an administrative account is needed.
- Beyond that, no action by a user is required.
Scoring
- CVSS
- 6.6 (v3.1)
- Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H- Weakness
- CWE-284
- Assigned by
- secalert_us@oracle.com
Dates
- Published
- 2026-08-18
- Last modified
- 2026-08-24
- Sources
- NVD
Affected products
- Oracle Hyperion Data Relationship Management11.2.25.0.000
As listed in the NVD configuration data. Not a statement about your estate.