Summary
CVE-2026-70883 is a critical (CVSS 9.1) vulnerability in the Access and security component of Oracle Hyperion Data Relationship Management (DRM). It allows an unauthenticated, remote attacker with only HTTP network access to the target system to gain unauthorized creation, deletion, or modification access to critical data and to view sensitive system information, without requiring any credentials or user interaction.
Technical details
- Root cause: A flaw in the Access and security component of Oracle Hyperion Data Relationship Management that fails to properly enforce authorization/access controls on requests reaching the application over HTTP.
- Trigger conditions: No authentication, privileges, or user interaction are required — the attacker only needs network-level access to the DRM HTTP interface.
- Attack vector: Network (AV:N), with low attack complexity (AC:L), making the flaw straightforward to exploit against internet- or intranet-exposed instances.
- Impact: High confidentiality impact (unauthorized access to system data) and high integrity impact (unauthorized creation, deletion, or modification of critical data), with no direct impact on availability.
Affected software
- Oracle Hyperion Data Relationship Management, version 11.2.25.0.000
Severity
- CVSS v3.1 Base Score: 9.1 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Mitigation and recommended actions
- Immediate: Apply the Oracle Critical Security Patch Update for August 2026, which addresses this vulnerability in Oracle Hyperion Data Relationship Management. Organizations running version 11.2.25.0.000 should prioritize patching given the unauthenticated, network-exploitable nature of this flaw.
- If immediate patching is not possible: Restrict network exposure of the DRM HTTP interface — ensure it is not reachable from the public internet, and limit access to trusted internal networks or VPN-only access via firewall rules and network segmentation until the patch can be applied. Monitor DRM access logs for unexpected or unauthenticated data-modification requests.

