PatchSiren cyber security CVE debrief
CVE-2026-70900 Oracle Corporation CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:47.700Z and has not been modified since then. This vulnerability affects Oracle Hyperion Data Relationship Management, specifically version 11.2.25.0.000, and is difficult to exploit. It allows unauthenticated attackers with network access via HTTP to compromise the system, potentially impacting additional products. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data, as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. The CVSS 3.1 Base Score is 8.7, indicating high severity. Organizations using Oracle Hyperion Data Relationship Management, security teams, and IT administrators should be aware of this vulnerability and assess their deployments for potential exposure. They should prioritize patching or mitigation efforts and verify system configurations to minimize potential impact. Evidence from Oracle and NVD indicates a high-severity vulnerability, but details are limited, and further verification is needed to assess the full impact and confirm affected deployments.
- Vendor
- Oracle Corporation
- Product
- Oracle Hyperion Data Relationship Management
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-18
- Original CVE updated
- 2026-08-22
- Advisory published
- 2026-08-18
- Advisory updated
- 2026-08-22
Who should care
Organizations using Oracle Hyperion Data Relationship Management, security teams, and IT administrators should be aware of this vulnerability. They should assess their deployments for potential exposure and prioritize patching or mitigation efforts. Additionally, defenders should verify system configurations and monitor for suspicious activity to minimize potential impact.
Technical summary
A difficult-to-exploit vulnerability in Oracle Hyperion Data Relationship Management allows unauthenticated attackers with network access via HTTP to compromise the system, potentially impacting additional products. The supported version that is affected is 11.2.25.0.000. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data.
Defensive priority
High priority due to potential unauthorized access and data modification
Recommended defensive actions
- Apply vendor patches or updates
- Restrict network access to Oracle Hyperion Data Relationship Management
- Monitor for suspicious activity
- Verify system configurations and inventory
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
Evidence from Oracle and NVD indicates a high-severity vulnerability in Oracle Hyperion Data Relationship Management, but details are limited. The CVE record was published on 2026-08-18T21:17:47.700Z and has not been modified since then. Further verification is needed to assess the full impact and to confirm affected deployments.
Official resources
-
CVE-2026-70900 CVE record
CVE.org
-
CVE-2026-70900 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:47.700Z and has not been modified since then.