PT-2026-3672 · Oracle · Oracle Planning/Budgeting Cloud Service+1
Patrick Murphy
·
Published
2026-01-20
·
Updated
2026-01-21
·
CVE-2026-21922
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:S/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle Planning and Budgeting Cloud Service versions 25.04.07
Description
A flaw exists in the Oracle Planning and Budgeting Cloud Service, specifically within the EPM Agent component. A highly privileged attacker with access to the system can compromise the service. Exploitation requires interaction from a user other than the attacker and can lead to unauthorized modification, deletion, or creation of data within Oracle Planning and Budgeting Cloud Service.
Recommendations
Update EPM Agent. Refer to documentation for downloading the EPM Agent.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Epm Agent
Oracle Planning/Budgeting Cloud Service