Summary
CVE-2026-70872 is a critical, unauthenticated vulnerability in the "Access and security" component of Oracle Hyperion Data Relationship Management (DRM). An attacker with only network access to the affected HTTP interface — no credentials or user interaction required — can exploit the flaw to read, create, delete, or modify critical data within the application. Oracle rates the issue 9.1 (Critical) on the CVSS v3.1 scale and disclosed it as part of its August 2026 Critical Security Patch Update.
Technical details
- Root cause: A weakness in Hyperion DRM’s access and security controls allows the enforcement of authentication/authorization to be bypassed for certain operations.
- Trigger conditions: The vulnerability is reachable by any attacker who can send HTTP requests to the exposed Hyperion DRM service; no valid account, prior access, or victim interaction is needed.
- Attack vector: Network (AV:N), over HTTP, with low attack complexity (AC:L) — Oracle describes it as "easily exploitable."
- Impact: Successful exploitation grants unauthorized creation, deletion, or modification of critical/all DRM-accessible data, as well as unauthorized read access to critical/all DRM-accessible data. There is no direct impact on availability.
- Oracle’s August 2026 Critical Security Patch Update lists this issue alongside several related CVEs (e.g., CVE-2026-70871, CVE-2026-70873) affecting the same "Access and security" component of Hyperion DRM, all similarly remotely exploitable without authentication.
Affected software
- Oracle Hyperion Data Relationship Management, version 11.2.25.0.000
Severity
- CVSS v3.1 Base Score: 9.1 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Mitigation and recommended actions
- Immediate: Apply the fix provided in Oracle’s August 2026 Critical Security Patch Update for Oracle Hyperion Data Relationship Management. Oracle states patches must be applied through the mechanisms accompanying that Critical Security Patch Update; there is no indication that patching in isolation (without applying the full update) is supported.
- If immediate patching is not possible: Restrict network access to the Hyperion DRM HTTP service to trusted internal networks/VPNs only, and place it behind an authenticated reverse proxy or web application firewall until the patch can be applied, since the flaw requires no authentication and is directly reachable over HTTP.
- Review Hyperion DRM audit/access logs for anomalous unauthenticated data creation, deletion, or modification activity that may indicate attempted or successful exploitation.

