The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
3,089 vulnerabilities with CWE-269
CVE-2026-60932
HIGH
Oracle Labor Distribution 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60931
HIGH
Oracle Public Sector Financials 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.5
CVE-2026-60927
HIGH
Oracle Public Sector Financials 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.5
CVE-2026-60925
HIGH
Oracle Public Sector Payroll 12.2.4-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.2
CVE-2026-60924
HIGH
Oracle Public Sector Payroll 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60920
HIGH
Oracle Customer Care 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60918
HIGH
Oracle Shipping Execution 12.2.12-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.2
CVE-2026-60901
HIGH
Oracle Project Intelligence 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60900
HIGH
Oracle HCM Configuration Workbench 12.2.3-12.2.15 - Authenticated Remote Takeover via Rapid Implementation Component
CVSS 7.2
CVE-2026-60898
HIGH
Oracle Warehouse Management 12.2.3-12.2.15 - Authenticated Remote Code Execution via Internal Operations Component
CVSS 8.8
CVE-2026-60897
HIGH
Oracle Payroll 12.2.3-12.2.15 - Authenticated Remote Code Execution via Internal Operations Component
CVSS 8.8
CVE-2026-60894
HIGH
Oracle Payroll 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.5
CVE-2026-60890
HIGH
Oracle Payroll 12.2.3-12.2.15 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-60886
HIGH
Oracle Work in Process 12.2.3-12.2.15 - Authenticated Data Access and Modification via HTTP with User Interaction
CVSS 7.6
CVE-2026-60872
HIGH
Oracle Order Management 12.2.3-12.2.15 - Authenticated Remote Code Execution via Product Diagnostic Tools
CVSS 8.8
CVE-2026-60863
HIGH
Oracle Advanced Pricing 12.2.3-12.2.15 - Authenticated Remote Takeover via Pricing Installation Component
CVSS 8.8
CVE-2026-60859
HIGH
Oracle Quoting 12.2.3-12.2.15 - Authenticated Remote Code Execution via Internal Operations Component
CVSS 7.5
CVE-2026-60855
HIGH
Oracle Quality 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.5
CVE-2026-60854
HIGH
Oracle Quality < 12.2.15 - Denial of Service
CVSS 8.2
CVE-2026-60847
LOW
Oracle Order Entry < 12.2.15 - Denial of Service
CVSS 3.4
CVE-2026-60837
HIGH
Oracle Price Protection 12.2.3-12.2.15: Authenticated Critical Data Manipulation & Unauthorized Access via Internal Ops
CVSS 8.4
CVE-2026-60836
HIGH
Oracle HCM Common Architecture 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.2
CVE-2026-60833
HIGH
Oracle Solaris 11.4 - Local Privilege Escalation via Utility Component
CVSS 7.0
CVE-2026-60719
CRITICAL
Oracle BI Publisher - Denial of Service
CVSS 9.9
CVE-2026-60678
HIGH
Oracle General Ledger 12.2.3-12.2.15 - Authenticated Remote Code Execution via SOAP
CVSS 8.8
Details
Vulnerabilities
3,089
Exploit Likelihood
Medium