CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
6,227 vulnerabilities with CWE-284
CVE-2026-61130
CRITICAL
Oracle Commerce Platform - Denial of Service
CVSS 9.1
CVE-2026-61127
HIGH
Oracle Communications Service Catalog/Design 8.0.0.7.0-8.3.0.2.0 Auth RCE via Solution Designer
CVSS 8.8
CVE-2026-61122
HIGH
Oracle HRMS (UK) 12.2.9-12.2.15 - Authenticated Data Modification and Unauthorized Data Access via UK Payroll Component
CVSS 8.1
CVE-2026-61121
HIGH
Oracle HRMS (UK) 12.2.8-12.2.15 - Authenticated Remote Code Execution via UK Payroll Component
CVSS 8.8
CVE-2026-61119
HIGH
Oracle Hrms (uk) < 12.2.15 - Denial of Service
CVSS 7.1
CVE-2026-61117
MEDIUM
Oracle HRMS (UK) 12.2.8-12.2.15 - Authenticated Data Access via Internal Operations Component
CVSS 6.3
CVE-2026-61115
HIGH
Oracle Order Management 12.2.3-12.2.15 - Authenticated Remote Code Execution via Product Diagnostic Tools
CVSS 7.2
CVE-2026-61113
HIGH
Oracle Application Object Library 12.2.3-12.2.15 - Unauthenticated Critical Data Access and Modification via HTTP
CVSS 7.4
CVE-2026-61112
MEDIUM
Oracle Order Management 12.2.3-12.2.15 - Authenticated Unauthorized Data Access via Product Diagnostic Tools
CVSS 6.5
CVE-2026-61111
MEDIUM
Oracle App Object Library 12.2.3-12.2.15: Authenticated Critical Data Access via Local Logon
CVSS 6.5
CVE-2026-61106
HIGH
Oracle GoldenGate 23.4-23.26.2 - Unauthenticated Remote Code Execution via Config Service Executable
CVSS 8.1
CVE-2026-61105
HIGH
Oracle Banking Trade Finance 14.6.0-14.8.0 - Authenticated Data Creation, Deletion and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-61103
MEDIUM
PeopleSoft Enterprise CS Campus Community 9.2.38 - Unauthenticated Data Access/Modification via Network
CVSS 5.9
CVE-2026-61102
HIGH
Oracle Banking Trade Finance 14.6.0-14.8.0 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-61101
HIGH
Oracle MES for Process Manufacturing 12.2.3-12.2.15: Unauthenticated Data Access/Mod via HTTP w/ User Interaction
CVSS 8.2
CVE-2026-61099
HIGH
Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Client Bundle
CVSS 8.8
CVE-2026-61098
HIGH
Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-61097
CRITICAL
Oracle Banking Trade Finance Process Management < 14.8.0 - Denial of Service
CVSS 9.6
CVE-2026-61096
LOW
MySQL Server and MySQL Cluster - Unauthenticated Data Manipulation via Pluggable Authentication
CVSS 2.9
CVE-2026-61095
HIGH
Oracle Communications Unified Inventory Management 7.5.0-8.0.1 - Authenticated Data Access and Modification via HTTP
CVSS 7.1
CVE-2026-61094
HIGH
MySQL 8.0.0-8.0.47, 8.4.0-8.4.1, 9.7.0-9.7.1 Authenticated Remote Takeover via Replication
CVSS 7.2
CVE-2026-61092
HIGH
Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 8.1
CVE-2026-61089
HIGH
PeopleSoft Enterprise SCM Inventory 9.2 - Unauthenticated Data Access and Modification via HTTP
CVSS 8.2
CVE-2026-61088
HIGH
PeopleSoft Enterprise SCM Manufacturing 9.2 - Unauthenticated Unauthorized Data Access via HTTP
CVSS 7.5
CVE-2026-61087
HIGH
PeopleSoft Enterprise FIN Payables 9.2 - Unauthenticated Unauthorized Data Access via HTTP
CVSS 7.5
Details
Vulnerabilities
6,227