CWE-269

Medium likelihood

Improper Privilege Management

Parent: CWE-284 - Improper Access Control

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

3,089 vulnerabilities with CWE-269
CVE-2026-60932 HIGH
Oracle Labor Distribution 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60931 HIGH
Oracle Public Sector Financials 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.5
CVE-2026-60927 HIGH
Oracle Public Sector Financials 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.5
CVE-2026-60925 HIGH
Oracle Public Sector Payroll 12.2.4-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.2
CVE-2026-60924 HIGH
Oracle Public Sector Payroll 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60920 HIGH
Oracle Customer Care 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60918 HIGH
Oracle Shipping Execution 12.2.12-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.2
CVE-2026-60901 HIGH
Oracle Project Intelligence 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60900 HIGH
Oracle HCM Configuration Workbench 12.2.3-12.2.15 - Authenticated Remote Takeover via Rapid Implementation Component
CVSS 7.2
CVE-2026-60898 HIGH
Oracle Warehouse Management 12.2.3-12.2.15 - Authenticated Remote Code Execution via Internal Operations Component
CVSS 8.8
CVE-2026-60897 HIGH
Oracle Payroll 12.2.3-12.2.15 - Authenticated Remote Code Execution via Internal Operations Component
CVSS 8.8
CVE-2026-60894 HIGH
Oracle Payroll 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.5
CVE-2026-60890 HIGH
Oracle Payroll 12.2.3-12.2.15 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-60886 HIGH
Oracle Work in Process 12.2.3-12.2.15 - Authenticated Data Access and Modification via HTTP with User Interaction
CVSS 7.6
CVE-2026-60872 HIGH
Oracle Order Management 12.2.3-12.2.15 - Authenticated Remote Code Execution via Product Diagnostic Tools
CVSS 8.8
CVE-2026-60863 HIGH
Oracle Advanced Pricing 12.2.3-12.2.15 - Authenticated Remote Takeover via Pricing Installation Component
CVSS 8.8
CVE-2026-60859 HIGH
Oracle Quoting 12.2.3-12.2.15 - Authenticated Remote Code Execution via Internal Operations Component
CVSS 7.5
CVE-2026-60855 HIGH
Oracle Quality 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.5
CVE-2026-60854 HIGH
Oracle Quality < 12.2.15 - Denial of Service
CVSS 8.2
CVE-2026-60847 LOW
Oracle Order Entry < 12.2.15 - Denial of Service
CVSS 3.4
CVE-2026-60837 HIGH
Oracle Price Protection 12.2.3-12.2.15: Authenticated Critical Data Manipulation & Unauthorized Access via Internal Ops
CVSS 8.4
CVE-2026-60836 HIGH
Oracle HCM Common Architecture 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.2
CVE-2026-60833 HIGH
Oracle Solaris 11.4 - Local Privilege Escalation via Utility Component
CVSS 7.0
CVE-2026-60719 CRITICAL
Oracle BI Publisher - Denial of Service
CVSS 9.9
CVE-2026-60678 HIGH
Oracle General Ledger 12.2.3-12.2.15 - Authenticated Remote Code Execution via SOAP
CVSS 8.8
Details
Vulnerabilities 3,089
Exploit Likelihood Medium