CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

6,227 vulnerabilities with CWE-284
CVE-2026-61164 HIGH
Oracle Commerce Guided Search/Experience Manager 11.4.0 - Unauth Data Modification & Info Disclosure via CAS
CVSS 7.4
CVE-2026-61162 HIGH
Oracle Commerce Guided Search / Oracle Commerce Experience Manager - Improper Access Control
CVSS 7.1
CVE-2026-61161 CRITICAL
Oracle Commerce Guided Search/Experience Manager 11.4.0 - Unauth RCE via Endeca Controller
CVSS 9.8
CVE-2026-61160 HIGH
Oracle Commerce Guided Search / Oracle Commerce Experience Manager - Denial of Service
CVSS 8.1
CVE-2026-61158 HIGH
Oracle Commerce Guided Search and Experience Manager 11.4.0 - Unauthenticated Unauthorized Data Access via RMI
CVSS 7.5
CVE-2026-61157 HIGH
Oracle Commerce Guided Search and Experience Manager 11.4.0 - Unauthenticated Unauthorized Data Access via HTTP
CVSS 7.5
CVE-2026-61156 CRITICAL
Oracle Commerce Guided Search 11.4.0 - Unauthenticated Critical Data Access & Modification via Forge
CVSS 9.1
CVE-2026-61155 CRITICAL
Oracle Commerce Guided Search Platform Services - Denial of Service
CVSS 9.1
CVE-2026-61153 CRITICAL
Oracle Commerce Guided Search/Experience Manager 11.4.0 - Unauthenticated Critical Data Access/Modification
CVSS 9.1
CVE-2026-61152 MEDIUM
Oracle Commerce Guided Search/Experience Manager 11.4.0 - Authenticated Data Modification & Info Disclosure
CVSS 5.4
CVE-2026-61151 HIGH
Oracle Commerce Guided Search and Experience Manager 11.4.0 - Authenticated Data Access and Modification via HTTP
CVSS 7.1
CVE-2026-61150 HIGH
Oracle Commerce Guided Search/Experience Manager 11.4.0: Authenticated Data Manipulation & Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-61149 HIGH
Oracle Commerce Guided Search and Experience Manager 11.4.0 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-61148 HIGH
Oracle Commerce Guided Search and Experience Manager 11.4.0 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-61146 CRITICAL
Oracle Commerce Guided Search/Experience Manager 11.4.0 - Auth RCE via Content Acquisition System
CVSS 9.9
CVE-2026-61145 CRITICAL
Oracle Commerce Guided Search/Experience Manager 11.4.0 - Unauth RCE via Content Acquisition System
CVSS 9.8
CVE-2026-61143 MEDIUM
Oracle Communications Convergent Charging Controller 15.0.0.0.0/15.2.0.0.0 Auth Bypass RCE via Prov IF
CVSS 6.4
CVE-2026-61142 HIGH
Oracle Payroll 12.2.3-12.2.15 - Authenticated Sensitive Data Exposure via HTTP Request
CVSS 7.7
CVE-2026-61141 HIGH
Oracle Advanced Benefits 12.2.7-12.2.15 - Authenticated Remote Takeover via Affordable Care Act Component
CVSS 7.5
CVE-2026-61140 CRITICAL
Oracle WebCenter Sites 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-61138 HIGH
Oracle Complex Maintenance, Repair and Overhaul 12.2.3-12.2.15 - Unauthenticated Data Access and Modification via HTTP
CVSS 7.5
CVE-2026-61136 HIGH
Oracle Commerce Platform - Denial of Service
CVSS 7.3
CVE-2026-61135 HIGH
Oracle Commerce 11.4.0: Unauthenticated Data Creation/Deletion & Unauthorized Access via Dynamo Framework
CVSS 7.4
CVE-2026-61134 MEDIUM
Oracle Commerce 11.4.0: Authenticated Data Manipulation & Unauthorized Access via Dynamo Framework
CVSS 6.8
CVE-2026-61131 CRITICAL
Oracle Commerce Platform 11.4.0 - Unauthenticated Remote Code Execution via Dynamo Application Framework
CVSS 9.8
Details
Vulnerabilities 6,227