PatchSiren cyber security CVE debrief
CVE-2026-70903 Oracle Corporation CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:48.050Z and has not been modified since then. The CVE-2026-70903 vulnerability affects Oracle Hyperion Data Relationship Management, version 11.2.25.0.000, and allows low-privileged attackers with network access via HTTPS to compromise the product. Successful attacks require human interaction and can result in unauthorized access to critical data or complete access to all accessible data. Organizations should prioritize patching this vulnerability to prevent potential attacks. Additionally, security teams and administrators responsible for Oracle products should be aware of this vulnerability and take necessary actions to mitigate the risk. The vulnerability has a CVSS score of 8.7 and is considered high-severity.
- Vendor
- Oracle Corporation
- Product
- Oracle Hyperion Data Relationship Management
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-18
- Original CVE updated
- 2026-08-22
- Advisory published
- 2026-08-18
- Advisory updated
- 2026-08-22
Who should care
Organizations using Oracle Hyperion Data Relationship Management version 11.2.25.0.000 should prioritize patching this vulnerability to prevent potential attacks. Additionally, security teams and administrators responsible for Oracle products should be aware of this vulnerability and take necessary actions to mitigate the risk.
Technical summary
The CVE-2026-70903 vulnerability is a high-severity issue in Oracle Hyperion Data Relationship Management, version 11.2.25.0.000. It has a CVSS score of 8.7 and allows low-privileged attackers with network access via HTTPS to compromise the product. Successful attacks require human interaction and can result in unauthorized creation, deletion, or modification access to critical data and unauthorized access to critical or all accessible data. The vulnerability potentially impacts additional products and has a significant impact on the confidentiality and integrity of the affected system. To mitigate this vulnerability, it is essential to review and apply Oracle's security patches for Oracle Hyperion Data Relationship Management version 11.2.25.0.000, implement network access controls, monitor for suspicious activity, and educate users on the importance of human interaction in preventing successful attacks.
Defensive priority
High priority due to high CVSS score of 8.7 and potential for significant impact on additional products.
Recommended defensive actions
- Review and apply Oracle's security patches for Oracle Hyperion Data Relationship Management version 11.2.25.0.000.
- Implement network access controls to limit access to Oracle Hyperion Data Relationship Management.
- Monitor for suspicious activity and implement logging and auditing to detect potential attacks.
- Educate users on the importance of human interaction in preventing successful attacks.
- Consider implementing compensating controls, such as Web Application Firewalls, to detect and prevent attacks.
Evidence notes
The CVE-2026-70903 vulnerability affects Oracle Hyperion Data Relationship Management, version 11.2.25.0.000. It allows low-privileged attackers with network access via HTTPS to compromise the product, potentially impacting additional products. Successful attacks require human interaction. The vulnerability results in unauthorized creation, deletion, or modification access to critical data and unauthorized access to critical or all accessible data.
Official resources
-
CVE-2026-70903 CVE record
CVE.org
-
CVE-2026-70903 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:48.050Z and has not been modified since then.