CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
6,232 vulnerabilities with CWE-284
CVE-2026-60659
HIGH
Oracle Solaris - Denial of Service
CVSS 7.1
CVE-2026-60657
HIGH
Oracle WebCenter Content 12.2.1.4.0/14.1.2.0.0: Authenticated Data Modification & Unauthorized Access
CVSS 7.7
CVE-2026-60656
HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Web Content Management
CVSS 8.8
CVE-2026-60655
HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Web Content Management
CVSS 8.8
CVE-2026-60654
HIGH
Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0 - Authenticated Remote Code Execution via Web Content Management
CVSS 8.8
CVE-2026-60651
HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via Web Content Management
CVSS 8.8
CVE-2026-60649
CRITICAL
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Arbitrary Data Creation, Deletion, and Access via HTTP
CVSS 9.1
CVE-2026-60647
HIGH
Oracle WebCenter Content - Denial of Service
CVSS 7.1
CVE-2026-60645
HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Web Content Management
CVSS 7.2
CVE-2026-60642
HIGH
Oracle WebCenter Content - Denial of Service
CVSS 7.6
CVE-2026-60641
HIGH
Oracle WebCenter Content - Denial of Service
CVSS 7.6
CVE-2026-60632
CRITICAL
Oracle WebCenter Content 12.2.1.4.0/14.1.2.0.0: Unauth HTTP Arbitrary Data Creation, Modification, Access
CVSS 9.3
CVE-2026-60631
CRITICAL
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Arbitrary Data Creation, Deletion, and Access via HTTP
CVSS 9.3
CVE-2026-60630
MEDIUM
Oracle APEX 24.1, 24.2, and 26.1 - Authenticated Unauthorized Data Access via Installation Component
CVSS 5.5
CVE-2026-60629
HIGH
Oracle JDeveloper 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Data Exposure and Unauthorized Data Modification via HTTP
CVSS 7.5
CVE-2026-60628
LOW
JD Edwards EnterpriseOne Tools 9.2.26.3 - Unauthenticated Data Modification & Info Disclosure via Physical Access
CVSS 3.7
CVE-2026-60626
MEDIUM
JD Edwards EnterpriseOne Tools 9.2.26.3: Authenticated Critical Data Creation/Deletion/Mod via Install Security
CVSS 6.0
CVE-2026-60622
HIGH
Oracle JDeveloper 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Sensitive Data Exposure via HTTP
CVSS 7.5
CVE-2026-60620
MEDIUM
Oracle Corporation JD Edwards EnterpriseOne Configurator - Denial of Service
CVSS 6.4
CVE-2026-60619
HIGH
JD Edwards EnterpriseOne HCM 9.2 Authenticated RCE via Time Accounting & HRM Base Component
CVSS 7.5
CVE-2026-60617
MEDIUM
PeopleSoft Enterprise CS Campus Community 9.2.38 - Unauthenticated Data Modification and Information Disclosure via HTTP
CVSS 6.5
CVE-2026-60614
HIGH
Oracle Corporation PeopleSoft Enterprise CS Campus Community - Denial of Service
CVSS 7.1
CVE-2026-60613
MEDIUM
PeopleSoft Enterprise CS Student Records 9.2.38 - Remote System Takeover via Research Tracking Component
CVSS 6.6
CVE-2026-60612
MEDIUM
Oracle PeopleSoft Financial Aid 9.2.38 - Unauthorized Data Access and Modification
CVSS 6.8
CVE-2026-60608
MEDIUM
PeopleSoft Enterprise CS Financial Aid 9.2.38 - Authenticated Data Modification & Info Disclosure
CVSS 6.1
Details
Vulnerabilities
6,232