The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
3,089 vulnerabilities with CWE-269
CVE-2026-61107
HIGH
Oracle Applications DBA 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.2
CVE-2026-61099
HIGH
Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Client Bundle
CVSS 8.8
CVE-2026-61098
HIGH
Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-61094
HIGH
MySQL 8.0.0-8.0.47, 8.4.0-8.4.1, 9.7.0-9.7.1 Authenticated Remote Takeover via Replication
CVSS 7.2
CVE-2026-61091
HIGH
Oracle Communications Billing and Revenue Management 15.0.0.0.0-15.2.0.0.0 Authenticated RCE via BRM Server
CVSS 7.8
CVE-2026-61090
HIGH
Oracle Project Foundation 12.2.3-12.2.15 - Authenticated Remote Takeover via Local Access
CVSS 7.8
CVE-2026-61076
CRITICAL
PeopleSoft Enterprise HCM Talent Acquisition Manager 9.2 - Authenticated Remote Code Execution via Job Opening Component
CVSS 9.9
CVE-2026-61064
MEDIUM
Oracle iRecruitment 12.2.3-12.2.15 - Authenticated Data Modification and Information Disclosure via HTTP
CVSS 5.4
CVE-2026-61063
HIGH
PeopleSoft Enterprise SCM Supplier Contract Management 9.2 - Authenticated Remote Code Execution via Security Component
CVSS 8.8
CVE-2026-61062
HIGH
PeopleSoft Enterprise FIN Cash Management 9.2 - Authenticated Remote Code Execution via Cash Management Component
CVSS 8.8
CVE-2026-61061
HIGH
Oracle JDeveloper 12.2.1.4.0 and 14.1.2.0.0 - Authenticated Remote Code Execution via Security Framework
CVSS 7.0
CVE-2026-61055
HIGH
PeopleSoft Enterprise SCM Order Management 9.2 - Authenticated Remote Code Execution via Security Component
CVSS 7.8
CVE-2026-61053
HIGH
Oracle Communications BRM Elastic Charging Engine 15.0.0.0.0-15.2.0.0.0 Authenticated RCE via Diameter Gateway/SDK
CVSS 7.8
CVE-2026-61023
MEDIUM
Oracle Inventory Management 12.2.3-12.2.15 - Authenticated Remote Takeover via Internal Operations Component
CVSS 6.4
CVE-2026-61013
MEDIUM
Oracle Time and Labor 12.2.3-12.2.15 - Authenticated Data Access and Modification via HTTP
CVSS 6.6
CVE-2026-61010
HIGH
Oracle Process Manufacturing Systems 12.2.3-12.2.15 - Authenticated Remote System Takeover via HTTP
CVSS 8.8
CVE-2026-61006
HIGH
Oracle Process Manufacturing Logistics 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.2
CVE-2026-60989
HIGH
Oracle Advanced Collections 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60988
HIGH
Oracle Project Portfolio Analysis 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.5
CVE-2026-60973
HIGH
Oracle E-Business Tax 12.2.3-12.2.15 - Authenticated Remote Code Execution via Internal Operations Component
CVSS 7.8
CVE-2026-60957
MEDIUM
Oracle Transportation Execution 12.2.3-12.2.15 - Cross-Site Request Forgery via HTTP with Scope Change Impact
CVSS 5.4
CVE-2026-60952
HIGH
Oracle Transportation Execution 12.2.3-12.2.15 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-60943
HIGH
Oracle Service Fulfillment Manager 12.2.3-12.2.15 - Authenticated Remote Code Execution via Fulfillment Engine
CVSS 7.5
CVE-2026-60941
HIGH
Oracle Service Fulfillment Manager 12.2.3-12.2.15 Authenticated Data Modification & Unauthorized Access
CVSS 8.7
CVE-2026-60938
MEDIUM
Oracle Labor Distribution 12.2.3-12.2.15 - Authenticated Data Manipulation via Internal Operations Component
CVSS 4.1
Details
Vulnerabilities
3,089
Exploit Likelihood
Medium