PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-70890 Oracle Corporation CVE debrief

The CVE record for CVE-2026-70890 was published on 2026-08-18T21:17:45.693Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. This high-severity vulnerability in Oracle Hyperion Data Relationship Management allows unauthenticated attackers with network access via HTTP to compromise data confidentiality. The CVSS score is 7.5, indicating high severity, with potential for unauthorized access to critical data. Security teams should prioritize patching and monitoring due to the high severity and potential impact on data confidentiality. They should verify the Oracle Hyperion Data Relationship Management version and apply vendor patches or restrict network access. Additionally, they should review and update incident response plans for potential data breaches and implement compensating controls for data confidentiality. Limited details are available on the exploitability and affected versions beyond 11.2.25.0.000.

Vendor
Oracle Corporation
Product
Oracle Hyperion Data Relationship Management
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-18
Original CVE updated
2026-08-22
Advisory published
2026-08-18
Advisory updated
2026-08-22

Who should care

Security teams responsible for Oracle Hyperion Data Relationship Management should prioritize patching and monitoring due to the high severity and potential impact on data confidentiality. They should verify the Oracle Hyperion Data Relationship Management version and apply vendor patches or restrict network access. Additionally, they should review and update incident response plans for potential data breaches and implement compensating controls for data confidentiality.

Technical summary

CVE-2026-70890 is a high-severity vulnerability in Oracle Hyperion Data Relationship Management, allowing unauthenticated attackers with network access via HTTP to compromise data confidentiality. The CVSS score is 7.5, indicating high severity. The affected version is 11.2.25.0.000. Successful attacks can result in unauthorized access to critical data. Security teams should prioritize patching and monitoring due to the high severity and potential impact on data confidentiality.

Defensive priority

High priority due to high CVSS score of 7.5 and potential for unauthorized access to critical data.

Recommended defensive actions

  • Verify the Oracle Hyperion Data Relationship Management version is not 11.2.25.0.000 or apply vendor patches.
  • Restrict network access to Oracle Hyperion Data Relationship Management.
  • Monitor for suspicious activity related to Oracle Hyperion Data Relationship Management.
  • Implement compensating controls for data confidentiality.
  • Review and update incident response plans for potential data breaches.

Evidence notes

Evidence from the NVD and CVE.org indicates a vulnerability in Oracle Hyperion Data Relationship Management with a CVSS score of 7.5. Limited details are available on the exploitability and affected versions beyond 11.2.25.0.000. The CVE record was published on 2026-08-18T21:17:45.693Z and has not been modified since then. Security teams should verify the Oracle Hyperion Data Relationship Management version and apply vendor patches or restrict network access.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:45.693Z and has not been modified since then.