CWE-269

Medium likelihood

Improper Privilege Management

Parent: CWE-284 - Improper Access Control

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

3,089 vulnerabilities with CWE-269
CVE-2026-61107 HIGH
Oracle Applications DBA 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.2
CVE-2026-61099 HIGH
Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Client Bundle
CVSS 8.8
CVE-2026-61098 HIGH
Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-61094 HIGH
MySQL 8.0.0-8.0.47, 8.4.0-8.4.1, 9.7.0-9.7.1 Authenticated Remote Takeover via Replication
CVSS 7.2
CVE-2026-61091 HIGH
Oracle Communications Billing and Revenue Management 15.0.0.0.0-15.2.0.0.0 Authenticated RCE via BRM Server
CVSS 7.8
CVE-2026-61090 HIGH
Oracle Project Foundation 12.2.3-12.2.15 - Authenticated Remote Takeover via Local Access
CVSS 7.8
CVE-2026-61076 CRITICAL
PeopleSoft Enterprise HCM Talent Acquisition Manager 9.2 - Authenticated Remote Code Execution via Job Opening Component
CVSS 9.9
CVE-2026-61064 MEDIUM
Oracle iRecruitment 12.2.3-12.2.15 - Authenticated Data Modification and Information Disclosure via HTTP
CVSS 5.4
CVE-2026-61063 HIGH
PeopleSoft Enterprise SCM Supplier Contract Management 9.2 - Authenticated Remote Code Execution via Security Component
CVSS 8.8
CVE-2026-61062 HIGH
PeopleSoft Enterprise FIN Cash Management 9.2 - Authenticated Remote Code Execution via Cash Management Component
CVSS 8.8
CVE-2026-61061 HIGH
Oracle JDeveloper 12.2.1.4.0 and 14.1.2.0.0 - Authenticated Remote Code Execution via Security Framework
CVSS 7.0
CVE-2026-61055 HIGH
PeopleSoft Enterprise SCM Order Management 9.2 - Authenticated Remote Code Execution via Security Component
CVSS 7.8
CVE-2026-61053 HIGH
Oracle Communications BRM Elastic Charging Engine 15.0.0.0.0-15.2.0.0.0 Authenticated RCE via Diameter Gateway/SDK
CVSS 7.8
CVE-2026-61023 MEDIUM
Oracle Inventory Management 12.2.3-12.2.15 - Authenticated Remote Takeover via Internal Operations Component
CVSS 6.4
CVE-2026-61013 MEDIUM
Oracle Time and Labor 12.2.3-12.2.15 - Authenticated Data Access and Modification via HTTP
CVSS 6.6
CVE-2026-61010 HIGH
Oracle Process Manufacturing Systems 12.2.3-12.2.15 - Authenticated Remote System Takeover via HTTP
CVSS 8.8
CVE-2026-61006 HIGH
Oracle Process Manufacturing Logistics 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.2
CVE-2026-60989 HIGH
Oracle Advanced Collections 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60988 HIGH
Oracle Project Portfolio Analysis 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.5
CVE-2026-60973 HIGH
Oracle E-Business Tax 12.2.3-12.2.15 - Authenticated Remote Code Execution via Internal Operations Component
CVSS 7.8
CVE-2026-60957 MEDIUM
Oracle Transportation Execution 12.2.3-12.2.15 - Cross-Site Request Forgery via HTTP with Scope Change Impact
CVSS 5.4
CVE-2026-60952 HIGH
Oracle Transportation Execution 12.2.3-12.2.15 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-60943 HIGH
Oracle Service Fulfillment Manager 12.2.3-12.2.15 - Authenticated Remote Code Execution via Fulfillment Engine
CVSS 7.5
CVE-2026-60941 HIGH
Oracle Service Fulfillment Manager 12.2.3-12.2.15 Authenticated Data Modification & Unauthorized Access
CVSS 8.7
CVE-2026-60938 MEDIUM
Oracle Labor Distribution 12.2.3-12.2.15 - Authenticated Data Manipulation via Internal Operations Component
CVSS 4.1
Details
Vulnerabilities 3,089
Exploit Likelihood Medium