Vulnerability in Oracle Hyperion Planning and Budgeting Cloud Service
CVE-2026-21979
4.2MEDIUM
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 20 January 2026
What is CVE-2026-21979?
An improper authentication vulnerability exists in the Oracle Planning and Budgeting Cloud Service, specifically within the EPM Agent component. Attackers with high privileges who can log on to the infrastructure running the service may exploit this vulnerability, potentially leading to unauthorized access to sensitive data. To mitigate risks, users are advised to update to the latest version of the EPM Agent available. For further guidance, refer to official resources provided by Oracle.
Affected Version(s)
Oracle Planning and Budgeting Cloud Service 25.04.07