CWE-269

Medium likelihood

Improper Privilege Management

Parent: CWE-284 - Improper Access Control

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

3,090 vulnerabilities with CWE-269
CVE-2026-46964 CRITICAL
Oracle Universal Work Queue 12.2.3-12.2.15 - Remote Code Execution via Work Provider
CVSS 9.9
CVE-2026-46962 HIGH
Oracle Project Portfolio Analysis 12.2.3-12.2.15 - Authenticated Remote Code Execution
CVSS 8.8
CVE-2026-46961 HIGH
Oracle Project Portfolio Analysis 12.2.3-12.2.15 - Authenticated Remote Code Execution
CVSS 8.8
CVE-2026-46959 HIGH
Oracle Subledger Accounting 12.2.3-12.2.15 - Authenticated Remote Code Execution via HTTP
CVSS 7.5
CVE-2026-46958 HIGH
Oracle Subledger Accounting 12.2.3-12.2.15 - Remote Code Execution via HTTP
CVSS 7.5
CVE-2026-46953 HIGH
Oracle HRMS (UK) 12.2.3-12.2.15 - Authenticated Remote Code Execution via UK Payroll Component
CVSS 7.2
CVE-2026-46952 HIGH
Oracle Quality 12.2.3-12.2.15 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-46951 HIGH
Oracle Quality 12.2.3-12.2.15 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-46942 HIGH
Oracle Process Manufacturing Process Planning 12.2.3-12.2.15 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-46940 HIGH
Oracle Cost Management 12.2.3-12.2.15 - Authenticated Remote Code Execution in Cost Planning
CVSS 8.8
CVE-2026-46937 HIGH
Oracle iSetup 12.2.3-12.2.15 - Authenticated Remote Code Execution in General Ledger Update Transform
CVSS 8.8
CVE-2026-46935 HIGH
Oracle Complex Maintenance, Repair and Overhaul 12.2.3-12.2.15 - Remote Code Execution via HTTP
CVSS 7.5
CVE-2026-46934 HIGH
Oracle Complex Maintenance, Repair and Overhaul 12.2.3-12.2.15 - Remote Code Execution via HTTP
CVSS 7.5
CVE-2026-46933 CRITICAL
Oracle Applications Manager 12.2.3-12.2.15 - Authenticated Remote Code Execution via HTTP
CVSS 9.9
CVE-2026-46929 HIGH
Oracle Cost Management 12.2.3-12.2.15 - Authenticated Remote Code Execution in Cost Planning
CVSS 8.8
CVE-2026-46928 HIGH
Oracle Spares Management 12.2.3-12.2.15 - Authenticated Remote Code Execution via HTTPS
CVSS 8.8
CVE-2026-46922 HIGH
Oracle HR Intelligence 12.2.3-12.2.15 - Authenticated Remote Code Execution
CVSS 7.2
CVE-2026-46921 HIGH
Siebel CRM Cloud Applications 17.0-26.5 - Authenticated Remote Code Execution in Siebel Cloud Manager
CVSS 8.8
CVE-2026-46916 HIGH
Oracle Process Manufacturing 12.2.3-12.2.15 - Authenticated RCE in Quality Management
CVSS 8.8
CVE-2026-46914 HIGH
Oracle Solaris - Denial of Service
CVSS 7.1
CVE-2026-46903 HIGH
JD Edwards EnterpriseOne Tools 9.2.0.0-9.2.26.2 - Authenticated Remote Code Execution
CVSS 8.8
CVE-2026-46901 CRITICAL
Oracle Enterprise Command Center Framework - Denial of Service
CVSS 9.9
CVE-2026-46900 CRITICAL
Oracle Enterprise Command Center Framework V15 V16 - Remote Code Execution via HTTPS
CVSS 9.9
CVE-2026-46899 CRITICAL
Oracle Enterprise Command Center Framework V15 V16 - Unauthorized Data Access and Modification via HTTP
CVSS 9.6
CVE-2026-46895 CRITICAL
Oracle Enterprise Command Center Framework V15 and V16 - Remote Code Execution via HTTP
CVSS 9.9
Details
Vulnerabilities 3,090
Exploit Likelihood Medium