PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-70879 Oracle CVE debrief

The CVE-2026-70879 vulnerability is a difficult-to-exploit issue in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion, specifically in the Access and security component. The supported version that is affected is 11.2.25.0.000. This vulnerability allows a low-privileged attacker with logon access to the infrastructure where Oracle Hyperion Data Relationship Management executes to compromise the product. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products. Successful attacks can result in takeover of Oracle Hyperion Data Relationship Management. The CVSS 3.1 Base Score is 7.8, indicating high severity, with impacts on Confidentiality, Integrity, and Availability. Users of Oracle Hyperion Data Relationship Management version 11.2.25.0.000 should be concerned about this vulnerability due to its high severity and potential for significant impact. Oracle Hyperion Data Relationship Management users should prioritize patching due to the high CVSS score of 7.8 and potential for significant impact.

Vendor
Oracle
Product
Hyperion Data Relationship Management
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-18
Original CVE updated
2026-08-21
Advisory published
2026-08-18
Advisory updated
2026-08-21

Who should care

Users of Oracle Hyperion Data Relationship Management version 11.2.25.0.000 should be concerned about this vulnerability due to its high severity and potential for significant impact.

Technical summary

The CVE-2026-70879 vulnerability is in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion, specifically in the Access and security component. The supported version that is affected is 11.2.25.0.000. This difficult-to-exploit vulnerability allows a low-privileged attacker with logon access to the infrastructure where Oracle Hyperion Data Relationship Management executes to compromise the product. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products. Successful attacks can result in takeover of Oracle Hyperion Data Relationship Management. The CVSS 3.1 Base Score is 7.8, indicating high severity, with impacts on Confidentiality, Integrity, and Availability.

Defensive priority

Oracle Hyperion Data Relationship Management users should prioritize patching due to the high CVSS score of 7.8 and potential for significant impact.

Recommended defensive actions

  • Apply the patch from Oracle as soon as possible
  • Review and update access controls for Oracle Hyperion Data Relationship Management
  • Monitor for suspicious activity related to Oracle Hyperion Data Relationship Management
  • Verify the integrity of Oracle Hyperion Data Relationship Management installations
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE-2026-70879 vulnerability in Oracle Hyperion Data Relationship Management has a CVSS score of 7.8, indicating high severity. It is difficult to exploit, requiring a low-privileged attacker with logon access to the infrastructure. Successful attacks can lead to takeover of the product. The supported and affected version is 11.2.25.0.000.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:44.370Z and has not been modified since then.