PT-2026-3672 · Oracle · Oracle Planning/Budgeting Cloud Service+1

Patrick Murphy

·

Published

2026-01-20

·

Updated

2026-01-21

·

CVE-2026-21922

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Oracle Planning and Budgeting Cloud Service versions 25.04.07
Description A flaw exists in the Oracle Planning and Budgeting Cloud Service, specifically within the EPM Agent component. A highly privileged attacker with access to the system can compromise the service. Exploitation requires interaction from a user other than the attacker and can lead to unauthorized modification, deletion, or creation of data within Oracle Planning and Budgeting Cloud Service.
Recommendations Update EPM Agent. Refer to documentation for downloading the EPM Agent.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2026-00685
CVE-2026-21922

Affected Products

Epm Agent
Oracle Planning/Budgeting Cloud Service