CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

6,227 vulnerabilities with CWE-284
CVE-2026-61130 CRITICAL
Oracle Commerce Platform - Denial of Service
CVSS 9.1
CVE-2026-61127 HIGH
Oracle Communications Service Catalog/Design 8.0.0.7.0-8.3.0.2.0 Auth RCE via Solution Designer
CVSS 8.8
CVE-2026-61122 HIGH
Oracle HRMS (UK) 12.2.9-12.2.15 - Authenticated Data Modification and Unauthorized Data Access via UK Payroll Component
CVSS 8.1
CVE-2026-61121 HIGH
Oracle HRMS (UK) 12.2.8-12.2.15 - Authenticated Remote Code Execution via UK Payroll Component
CVSS 8.8
CVE-2026-61119 HIGH
Oracle Hrms (uk) < 12.2.15 - Denial of Service
CVSS 7.1
CVE-2026-61117 MEDIUM
Oracle HRMS (UK) 12.2.8-12.2.15 - Authenticated Data Access via Internal Operations Component
CVSS 6.3
CVE-2026-61115 HIGH
Oracle Order Management 12.2.3-12.2.15 - Authenticated Remote Code Execution via Product Diagnostic Tools
CVSS 7.2
CVE-2026-61113 HIGH
Oracle Application Object Library 12.2.3-12.2.15 - Unauthenticated Critical Data Access and Modification via HTTP
CVSS 7.4
CVE-2026-61112 MEDIUM
Oracle Order Management 12.2.3-12.2.15 - Authenticated Unauthorized Data Access via Product Diagnostic Tools
CVSS 6.5
CVE-2026-61111 MEDIUM
Oracle App Object Library 12.2.3-12.2.15: Authenticated Critical Data Access via Local Logon
CVSS 6.5
CVE-2026-61106 HIGH
Oracle GoldenGate 23.4-23.26.2 - Unauthenticated Remote Code Execution via Config Service Executable
CVSS 8.1
CVE-2026-61105 HIGH
Oracle Banking Trade Finance 14.6.0-14.8.0 - Authenticated Data Creation, Deletion and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-61103 MEDIUM
PeopleSoft Enterprise CS Campus Community 9.2.38 - Unauthenticated Data Access/Modification via Network
CVSS 5.9
CVE-2026-61102 HIGH
Oracle Banking Trade Finance 14.6.0-14.8.0 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-61101 HIGH
Oracle MES for Process Manufacturing 12.2.3-12.2.15: Unauthenticated Data Access/Mod via HTTP w/ User Interaction
CVSS 8.2
CVE-2026-61099 HIGH
Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Client Bundle
CVSS 8.8
CVE-2026-61098 HIGH
Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-61097 CRITICAL
Oracle Banking Trade Finance Process Management < 14.8.0 - Denial of Service
CVSS 9.6
CVE-2026-61096 LOW
MySQL Server and MySQL Cluster - Unauthenticated Data Manipulation via Pluggable Authentication
CVSS 2.9
CVE-2026-61095 HIGH
Oracle Communications Unified Inventory Management 7.5.0-8.0.1 - Authenticated Data Access and Modification via HTTP
CVSS 7.1
CVE-2026-61094 HIGH
MySQL 8.0.0-8.0.47, 8.4.0-8.4.1, 9.7.0-9.7.1 Authenticated Remote Takeover via Replication
CVSS 7.2
CVE-2026-61092 HIGH
Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 8.1
CVE-2026-61089 HIGH
PeopleSoft Enterprise SCM Inventory 9.2 - Unauthenticated Data Access and Modification via HTTP
CVSS 8.2
CVE-2026-61088 HIGH
PeopleSoft Enterprise SCM Manufacturing 9.2 - Unauthenticated Unauthorized Data Access via HTTP
CVSS 7.5
CVE-2026-61087 HIGH
PeopleSoft Enterprise FIN Payables 9.2 - Unauthenticated Unauthorized Data Access via HTTP
CVSS 7.5
Details
Vulnerabilities 6,227