Summary
CVE-2026-70884 is a critical vulnerability in Oracle Hyperion Data Relationship Management (DRM) affecting version 11.2.25.0.000. The flaw allows an unauthenticated, remote attacker to exploit the product’s SOAP interface to gain unauthorized access to create, modify, or delete critical data, without requiring any user interaction. Oracle rates this vulnerability 9.1 (Critical) on the CVSS v3.1 scale.
Technical details
- Root cause: Insufficient access control on Oracle Hyperion DRM’s SOAP-based web services, allowing requests to reach data-modification functionality without proper authentication checks.
- Trigger conditions: An attacker only needs network access to the exposed SOAP endpoint of a vulnerable Hyperion DRM instance — no valid credentials or user interaction are required.
- Attack vector: Network (remote), low attack complexity, no privileges required, no user interaction — consistent with Oracle’s classification of this issue as "easily exploitable."
- Impact: High confidentiality and integrity impact — successful exploitation permits unauthorized creation, modification, or deletion of critical data managed by the application. Availability is not impacted (no denial-of-service effect noted).
Affected software
- Oracle Hyperion Data Relationship Management, version 11.2.25.0.000
Severity
- CVSS v3.1 Base Score: 9.1 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Mitigation and recommended actions
- Immediate: Apply the Oracle Critical Patch Update (CPU) for August 2026, which addresses this vulnerability in Oracle Hyperion Data Relationship Management. Upgrade affected 11.2.25.0.000 deployments per Oracle’s published patch guidance.
- If immediate patching is not possible: Restrict network access to the Hyperion DRM SOAP interface to trusted internal networks or VPN only, and avoid exposing the DRM management interfaces directly to the internet. Monitor SOAP endpoint access logs for anomalous or unauthenticated requests as an interim compensating control until the patch is applied.

