Executive brief
A vulnerability exists in the Cost Planning component of Oracle Cost Management, a tool used by businesses to track and manage manufacturing and supply chain costs. An attacker with basic user access can exploit this flaw over the network to take full control of the Cost Management system. This could lead to the theft of sensitive financial data, unauthorized modification of cost records, or a complete disruption of cost planning operations.
Technical details
This vulnerability is classified under Improper Access Control and Missing Authentication for Critical Functions (CWE-284, CWE-306) within the Cost Planning component of Oracle Cost Management. It is easily exploitable by a low-privileged attacker with network access via HTTP. The flaw allows for a complete takeover of the affected component, impacting confidentiality, integrity, and availability. Affected versions range from 12.2.3 through 12.2.15. Security patches are typically released via Oracle's Critical Patch Update (CPU) program.
Affected products
- Oracle Cost Management 12.2.3-12.2.15
Timeline
- 2026-06-17: disclosed: Initial disclosure by Oracle
- 2026-06-17: advisory: NVD publication date