CWE-269

Medium likelihood

Improper Privilege Management

Parent: CWE-284 - Improper Access Control

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

3,089 vulnerabilities with CWE-269
CVE-2026-61304 MEDIUM
Oracle Price Protection < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-61243 HIGH
PeopleSoft Enterprise FIN Common Objects Argentina 9.1 - Authenticated Remote Code Execution via Staffing Component
CVSS 8.8
CVE-2026-61237 CRITICAL
Oracle Corporation PeopleSoft Enterprise Fin Common Objects Argentina - Denial of Service
CVSS 9.9
CVE-2026-61225 HIGH
Oracle Communications Converged Application Server 8.2 and 8.3 - Unauthenticated Remote Takeover via TCP/IP
CVSS 8.1
CVE-2026-61216 MEDIUM
Oracle Payroll < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-61209 CRITICAL
PeopleSoft In-Memory Project Discovery 9.2 - Authenticated Remote Takeover via HTTP
CVSS 9.9
CVE-2026-61204 CRITICAL
PeopleSoft Enterprise FIN Program Mgmt 9.2 Auth RCE via Primavera Integration
CVSS 9.0
CVE-2026-61203 CRITICAL
Oracle Corporation PeopleSoft Enterprise Fin Expenses - Denial of Service
CVSS 9.4
CVE-2026-61201 CRITICAL
PeopleSoft Enterprise CRM Common Objects 9.2.23 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.0
CVE-2026-61188 HIGH
Oracle Agile Product Lifecycle Management for Process 6.2.4 - Authenticated Remote Takeover via Installation Component
CVSS 7.5
CVE-2026-61182 MEDIUM
Oracle Agile Product Lifecycle Management for Process 6.2.4 - Authenticated Remote Takeover via Data Import Component
CVSS 6.7
CVE-2026-61180 HIGH
Oracle Agile PLM for Process 6.2.4: Auth RCE via Product Quality Management Component
CVSS 8.8
CVE-2026-61179 HIGH
Oracle Agile PLM for Process 6.2.4: Authenticated Remote Takeover via PQM Component
CVSS 8.8
CVE-2026-61176 MEDIUM
Oracle Product Lifecycle Analytics - Denial of Service
CVSS 6.7
CVE-2026-61168 HIGH
Oracle Agile PLM 9.3.6 - Authenticated Remote Code Execution via Security Component
CVSS 8.8
CVE-2026-61154 CRITICAL
Oracle Commerce Guided Search Platform Services 11.4.0 - Unauthenticated Remote Code Execution via Forge Component
CVSS 9.8
CVE-2026-61149 HIGH
Oracle Commerce Guided Search and Experience Manager 11.4.0 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-61146 CRITICAL
Oracle Commerce Guided Search/Experience Manager 11.4.0 - Auth RCE via Content Acquisition System
CVSS 9.9
CVE-2026-61141 HIGH
Oracle Advanced Benefits 12.2.7-12.2.15 - Authenticated Remote Takeover via Affordable Care Act Component
CVSS 7.5
CVE-2026-61127 HIGH
Oracle Communications Service Catalog/Design 8.0.0.7.0-8.3.0.2.0 Auth RCE via Solution Designer
CVSS 8.8
CVE-2026-61126 HIGH
Oracle Communications Billing and Revenue Mgmt 15.0.0.0.0-15.2.0.0.0 - Auth Remote Takeover via Component
CVSS 7.8
CVE-2026-61121 HIGH
Oracle HRMS (UK) 12.2.8-12.2.15 - Authenticated Remote Code Execution via UK Payroll Component
CVSS 8.8
CVE-2026-61120 HIGH
Oracle HRMS (US) 12.2.3-12.2.15 - Authenticated Remote Code Execution via Internal Operations Component
CVSS 7.0
CVE-2026-61114 HIGH
Oracle Application Object Library 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.5
CVE-2026-61110 HIGH
Oracle Applications DBA 12.2.3-12.2.15 - Authenticated Remote Code Execution via ADPatch Component
CVSS 8.8
Details
Vulnerabilities 3,089
Exploit Likelihood Medium