A critical vulnerability (CVE-2026-70880) has been disclosed in Oracle Hyperion Data Relationship Management, a component of the Oracle Hyperion platform. This high-severity flaw (CVSS 10.0) allows unauthenticated attackers to execute arbitrary code remotely via TCP network access, potentially leading to full system compromise. The vulnerability exists in the access and security component of the software, specifically affecting version 11.2.25.0.000. Exploitation requires no prior authentication, making it highly accessible to threat actors. Successful attacks could result in unauthorized control of affected systems, with potential cascading impacts across interconnected products due to scope changes. Organizations utilizing the affected version of Oracle Hyperion Data Relationship Management are strongly advised to apply vendor-provided patches immediately. Until remediated, network-level mitigations such as restricting unnecessary TCP access to the service should be implemented. Given the ease of exploitation and severe consequences, this vulnerability ranks as a critical priority for remediation. No evidence of active exploitation has been reported at the time of publication.