Vulnerability in Oracle Hyperion Planning and Budgeting Cloud Service
CVE-2026-21979

4.2MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
20 January 2026

What is CVE-2026-21979?

An improper authentication vulnerability exists in the Oracle Planning and Budgeting Cloud Service, specifically within the EPM Agent component. Attackers with high privileges who can log on to the infrastructure running the service may exploit this vulnerability, potentially leading to unauthorized access to sensitive data. To mitigate risks, users are advised to update to the latest version of the EPM Agent available. For further guidance, refer to official resources provided by Oracle.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Oracle Planning and Budgeting Cloud Service 25.04.07

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.