PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-70903 Oracle Corporation CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:48.050Z and has not been modified since then. The CVE-2026-70903 vulnerability affects Oracle Hyperion Data Relationship Management, version 11.2.25.0.000, and allows low-privileged attackers with network access via HTTPS to compromise the product. Successful attacks require human interaction and can result in unauthorized access to critical data or complete access to all accessible data. Organizations should prioritize patching this vulnerability to prevent potential attacks. Additionally, security teams and administrators responsible for Oracle products should be aware of this vulnerability and take necessary actions to mitigate the risk. The vulnerability has a CVSS score of 8.7 and is considered high-severity.

Vendor
Oracle Corporation
Product
Oracle Hyperion Data Relationship Management
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-18
Original CVE updated
2026-08-22
Advisory published
2026-08-18
Advisory updated
2026-08-22

Who should care

Organizations using Oracle Hyperion Data Relationship Management version 11.2.25.0.000 should prioritize patching this vulnerability to prevent potential attacks. Additionally, security teams and administrators responsible for Oracle products should be aware of this vulnerability and take necessary actions to mitigate the risk.

Technical summary

The CVE-2026-70903 vulnerability is a high-severity issue in Oracle Hyperion Data Relationship Management, version 11.2.25.0.000. It has a CVSS score of 8.7 and allows low-privileged attackers with network access via HTTPS to compromise the product. Successful attacks require human interaction and can result in unauthorized creation, deletion, or modification access to critical data and unauthorized access to critical or all accessible data. The vulnerability potentially impacts additional products and has a significant impact on the confidentiality and integrity of the affected system. To mitigate this vulnerability, it is essential to review and apply Oracle's security patches for Oracle Hyperion Data Relationship Management version 11.2.25.0.000, implement network access controls, monitor for suspicious activity, and educate users on the importance of human interaction in preventing successful attacks.

Defensive priority

High priority due to high CVSS score of 8.7 and potential for significant impact on additional products.

Recommended defensive actions

  • Review and apply Oracle's security patches for Oracle Hyperion Data Relationship Management version 11.2.25.0.000.
  • Implement network access controls to limit access to Oracle Hyperion Data Relationship Management.
  • Monitor for suspicious activity and implement logging and auditing to detect potential attacks.
  • Educate users on the importance of human interaction in preventing successful attacks.
  • Consider implementing compensating controls, such as Web Application Firewalls, to detect and prevent attacks.

Evidence notes

The CVE-2026-70903 vulnerability affects Oracle Hyperion Data Relationship Management, version 11.2.25.0.000. It allows low-privileged attackers with network access via HTTPS to compromise the product, potentially impacting additional products. Successful attacks require human interaction. The vulnerability results in unauthorized creation, deletion, or modification access to critical data and unauthorized access to critical or all accessible data.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:48.050Z and has not been modified since then.