PatchSiren cyber security CVE debrief
CVE-2026-70899 Oracle Corporation CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:47.587Z and has not been modified since then. The CVE-2026-70899 vulnerability affects Oracle Hyperion Data Relationship Management, version 11.2.25.0.000, and is an easily exploitable vulnerability that allows low-privileged attackers with network access via HTTP to compromise the system. Successful attacks can result in takeover of Oracle Hyperion Data Relationship Management. The CVSS 3.1 Base Score is 8.8, indicating high impacts on Confidentiality, Integrity, and Availability. This vulnerability is considered high severity due to its potential for system compromise and data breaches. Organizations should review system configurations, monitor system logs, and implement compensating controls to mitigate potential impacts.
- Vendor
- Oracle Corporation
- Product
- Oracle Hyperion Data Relationship Management
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-18
- Original CVE updated
- 2026-08-22
- Advisory published
- 2026-08-18
- Advisory updated
- 2026-08-22
Who should care
Organizations using Oracle Hyperion Data Relationship Management, version 11.2.25.0.000, should prioritize patching this vulnerability to prevent potential system compromise and data breaches. Security teams and vulnerability management teams should review system configurations, monitor system logs, and implement compensating controls to mitigate potential impacts. IT operators and administrators should ensure that all necessary security patches are applied and up-to-date.
Technical summary
The CVE-2026-70899 vulnerability affects Oracle Hyperion Data Relationship Management, version 11.2.25.0.000. It is an easily exploitable vulnerability that allows low-privileged attackers with network access via HTTP to compromise the system. Successful attacks can result in takeover of Oracle Hyperion Data Relationship Management. The CVSS 3.1 Base Score is 8.8, indicating high impacts on Confidentiality, Integrity, and Availability. This vulnerability is considered high severity due to its potential for system compromise and data breaches.
Defensive priority
High priority due to high CVSS score of 8.8 and potential for takeover of Oracle Hyperion Data Relationship Management.
Recommended defensive actions
- Review and apply Oracle's security patches for CVE-2026-70899
- Restrict network access to Oracle Hyperion Data Relationship Management
- Monitor system logs for suspicious activity
- Implement compensating controls to mitigate potential impacts
- Conduct a thorough review of system configurations and network access controls
- Verify that all necessary security patches are applied and up-to-date
- Track exceptions and retest remediated assets to ensure vulnerability is resolved
Evidence notes
Evidence from official CVE and NVD sources indicates a vulnerability in Oracle Hyperion Data Relationship Management with a CVSS score of 8.8. The vulnerability allows low-privileged attackers with network access via HTTP to compromise the system, potentially leading to takeover. Limited evidence suggests that this vulnerability may impact organizations using Oracle Hyperion Data Relationship Management, version 11.2.25.0.000. Defenders should verify system configurations, review network access controls, and monitor system logs for suspicious activity.
Official resources
-
CVE-2026-70899 CVE record
CVE.org
-
CVE-2026-70899 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:47.587Z and has not been modified since then.