CWE-269

Medium likelihood

Improper Privilege Management

Parent: CWE-284 - Improper Access Control

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

3,089 vulnerabilities with CWE-269
CVE-2026-60663 CRITICAL
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Web Content Management
CVSS 9.9
CVE-2026-60661 HIGH
Oracle Solaris 11.4 - Local Privilege Escalation via Filesystems Component
CVSS 7.8
CVE-2026-60654 HIGH
Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0 - Authenticated Remote Code Execution via Web Content Management
CVSS 8.8
CVE-2026-60625 HIGH
Oracle Data Integrator 12.2.1.4.0 and 14.1.2.0.0 - Authenticated Remote Code Execution via Studio Component
CVSS 7.8
CVE-2026-60619 HIGH
JD Edwards EnterpriseOne HCM 9.2 Authenticated RCE via Time Accounting & HRM Base Component
CVSS 7.5
CVE-2026-60583 HIGH
Oracle Transportation Management 6.5.3 - Authenticated Remote Takeover via Install Component
CVSS 8.8
CVE-2026-60576 HIGH
Oracle Enterprise Command Center Framework V16 - Authenticated Remote Code Execution via HTTP
CVSS 7.2
CVE-2026-60567 CRITICAL
Oracle Identity Manager 12.2.1.4.0/14.1.2.1.0 - Unauthenticated Critical Data Creation/Mod/Access via Legacy UI
CVSS 9.1
CVE-2026-60566 CRITICAL
Oracle WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via Runtime Tools Component
CVSS 9.8
CVE-2026-60546 HIGH
Oracle SOA Suite 12.2.1.4.0 and 14.1.2.0.0 - Authenticated Remote Takeover via Integration Business Insight
CVSS 7.2
CVE-2026-60532 CRITICAL
Oracle Identity Manager Connector 12.2.1.4.0 and 14.1.2.1.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-60530 HIGH
Oracle HTTP Server 14.1.2.0.0 - Local Privilege Escalation via mod_http2.so
CVSS 7.8
CVE-2026-60492 HIGH
Oracle Corporation JD Edwards EnterpriseOne Hcm Foundation - Denial of Service
CVSS 7.1
CVE-2026-60454 HIGH
Oracle HTTP Server 12.2.1.4.0 and 14.1.2.0.0 - Authenticated Remote Code Execution via Core Component
CVSS 7.8
CVE-2026-60419 HIGH
Oracle Unified Directory 12.2.1.4.0 and 14.1.2.1.0 - Authenticated Remote Takeover via LDAP
CVSS 8.8
CVE-2026-60418 HIGH
Oracle Unified Directory 12.2.1.4.0, 14.1.2.1.0 - Authenticated Remote Takeover via LDAP
CVSS 7.2
CVE-2026-60406 MEDIUM
TimesTen In-Memory Database 26.1.1.1.0 - Authenticated Remote Takeover via Kubernetes Operator
CVSS 6.7
CVE-2026-60342 MEDIUM
Oracle Access Manager 12.2.1.4.0 and 14.1.2.1.0 - Unauthenticated Information Disclosure via Authentication Engine
CVSS 5.3
CVE-2026-60340 HIGH
Oracle Project Costing 12.2.3-12.2.15 - Authenticated Remote Code Execution via Enterprise Command Center
CVSS 7.2
CVE-2026-60271 HIGH
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Authenticated Remote Code Execution
CVSS 7.8
CVE-2026-60248 CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution
CVSS 9.3
CVE-2026-60183 MEDIUM
MySQL 8.0.0-8.0.47, 8.4.0-8.4.1, 9.7.0-9.7.1 Auth RCE via Clone Plugin
CVSS 6.4
CVE-2026-60175 HIGH
Oracle DB 19.3-19.31/21.3-21.22/23.4-23.26.2: Auth RCE via Oracle Net in RDBMS
CVSS 8.8
CVE-2026-60162 MEDIUM
Oracle VM VirtualBox - Denial of Service
CVSS 6.1
CVE-2026-60150 HIGH
Oracle VM VirtualBox 7.2.12 - Local Privilege Escalation to Host Takeover
CVSS 7.8
Details
Vulnerabilities 3,089
Exploit Likelihood Medium