CVE-2026-70880Patch(oracle / hyperion_data_relationship_management)

LOWCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch oracle hyperion_data_relationship_management systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • hyperion_data_relationship_management

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-08-19); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
hyperion_data_relationship_management

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-08-19: 2Mentions · 2026-08-22: 1Mentions · 2026-08-27: 1PoC Mentioned / Linked · 2026-08-19: 1Patch / Workaround · 2026-08-22: 1Patch / Workaround · 2026-08-27: 1Technical Details · 2026-08-22: 108-1908-2208-27
Signal classification3 categories
Patch
250.0%
General
125.0%
PoC
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-192
General1PoC1
2026-08-221
Patch1
2026-08-271
Patch1
Full discourse4 posts
  • ExploitGrid@exploitgrid
    General

    🛡️ ExploitGrid Daily Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-61241 CVE-2026-70880 CVE-2026-70921 CVE-2026-73343 CVE-2026-75784 ..🧵👇

    Post summary

    The post merely lists five CVE identifiers with no further details, providing no insight into exploitation status, PoC, or mitigation.

    1100041
    35 followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    🔑 CVSS 10 in Oracle Hyperion Data Relationship Management (v11.2.25.0.000). CVE-2026-70880 hits the Access & Security component — no auth, network-exploitable, full system compromise possible. Patch now. #cybersecurity #ciso #cto #vulnerabilities #mssp https://secalerts.co/vulnerability/CVE-2026-70880?utm_campaign=x https://t.co/mZuVjt4FUE

    Post summary

    The tweet announces a critical CVSS 10 vulnerability in Oracle Hyperion Data Relationship Management and urges users to apply the available patch immediately.

    00010182
    878 followersView on X
  • ExploitGrid@exploitgrid
    PoC

    [CVE] CVE-2026-70880 [HIGH PRIORITY] 🔗 https://exploitgrid.net/cve/CVE-2026-70880

    Post summary

    The post highlights a high‑priority CVE and links to a site that likely contains a proof of concept, but no direct exploit code or technical details are included.

    1000023
    35 followersView on X
  • NCIIPC India@NCIIPC
    Patch

    #Oracle has released security update for Hyperion Data Relationship Management which address a critical vulnerability #CVE-2026-70880. https://www.oracle.com/security-alerts/cspuaug2026.html

    Post summary

    Oracle released a security update for Hyperion Data Relationship Management to address CVE-2026-70880.

    00000303
    8.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apporaclehyperion_data_relationship_management11.2.25.0.000--

Explore more