The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
3,089 vulnerabilities with CWE-269
CVE-2026-60663
CRITICAL
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Web Content Management
CVSS 9.9
CVE-2026-60661
HIGH
Oracle Solaris 11.4 - Local Privilege Escalation via Filesystems Component
CVSS 7.8
CVE-2026-60654
HIGH
Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0 - Authenticated Remote Code Execution via Web Content Management
CVSS 8.8
CVE-2026-60625
HIGH
Oracle Data Integrator 12.2.1.4.0 and 14.1.2.0.0 - Authenticated Remote Code Execution via Studio Component
CVSS 7.8
CVE-2026-60619
HIGH
JD Edwards EnterpriseOne HCM 9.2 Authenticated RCE via Time Accounting & HRM Base Component
CVSS 7.5
CVE-2026-60583
HIGH
Oracle Transportation Management 6.5.3 - Authenticated Remote Takeover via Install Component
CVSS 8.8
CVE-2026-60576
HIGH
Oracle Enterprise Command Center Framework V16 - Authenticated Remote Code Execution via HTTP
CVSS 7.2
CVE-2026-60567
CRITICAL
Oracle Identity Manager 12.2.1.4.0/14.1.2.1.0 - Unauthenticated Critical Data Creation/Mod/Access via Legacy UI
CVSS 9.1
CVE-2026-60566
CRITICAL
Oracle WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via Runtime Tools Component
CVSS 9.8
CVE-2026-60546
HIGH
Oracle SOA Suite 12.2.1.4.0 and 14.1.2.0.0 - Authenticated Remote Takeover via Integration Business Insight
CVSS 7.2
CVE-2026-60532
CRITICAL
Oracle Identity Manager Connector 12.2.1.4.0 and 14.1.2.1.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-60530
HIGH
Oracle HTTP Server 14.1.2.0.0 - Local Privilege Escalation via mod_http2.so
CVSS 7.8
CVE-2026-60492
HIGH
Oracle Corporation JD Edwards EnterpriseOne Hcm Foundation - Denial of Service
CVSS 7.1
CVE-2026-60454
HIGH
Oracle HTTP Server 12.2.1.4.0 and 14.1.2.0.0 - Authenticated Remote Code Execution via Core Component
CVSS 7.8
CVE-2026-60419
HIGH
Oracle Unified Directory 12.2.1.4.0 and 14.1.2.1.0 - Authenticated Remote Takeover via LDAP
CVSS 8.8
CVE-2026-60418
HIGH
Oracle Unified Directory 12.2.1.4.0, 14.1.2.1.0 - Authenticated Remote Takeover via LDAP
CVSS 7.2
CVE-2026-60406
MEDIUM
TimesTen In-Memory Database 26.1.1.1.0 - Authenticated Remote Takeover via Kubernetes Operator
CVSS 6.7
CVE-2026-60342
MEDIUM
Oracle Access Manager 12.2.1.4.0 and 14.1.2.1.0 - Unauthenticated Information Disclosure via Authentication Engine
CVSS 5.3
CVE-2026-60340
HIGH
Oracle Project Costing 12.2.3-12.2.15 - Authenticated Remote Code Execution via Enterprise Command Center
CVSS 7.2
CVE-2026-60271
HIGH
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Authenticated Remote Code Execution
CVSS 7.8
CVE-2026-60248
CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution
CVSS 9.3
CVE-2026-60183
MEDIUM
MySQL 8.0.0-8.0.47, 8.4.0-8.4.1, 9.7.0-9.7.1 Auth RCE via Clone Plugin
CVSS 6.4
CVE-2026-60175
HIGH
Oracle DB 19.3-19.31/21.3-21.22/23.4-23.26.2: Auth RCE via Oracle Net in RDBMS
CVSS 8.8
CVE-2026-60162
MEDIUM
Oracle VM VirtualBox - Denial of Service
CVSS 6.1
CVE-2026-60150
HIGH
Oracle VM VirtualBox 7.2.12 - Local Privilege Escalation to Host Takeover
CVSS 7.8
Details
Vulnerabilities
3,089
Exploit Likelihood
Medium