CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

6,232 vulnerabilities with CWE-284
CVE-2026-60659 HIGH
Oracle Solaris - Denial of Service
CVSS 7.1
CVE-2026-60657 HIGH
Oracle WebCenter Content 12.2.1.4.0/14.1.2.0.0: Authenticated Data Modification & Unauthorized Access
CVSS 7.7
CVE-2026-60656 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Web Content Management
CVSS 8.8
CVE-2026-60655 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Web Content Management
CVSS 8.8
CVE-2026-60654 HIGH
Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0 - Authenticated Remote Code Execution via Web Content Management
CVSS 8.8
CVE-2026-60651 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via Web Content Management
CVSS 8.8
CVE-2026-60649 CRITICAL
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Arbitrary Data Creation, Deletion, and Access via HTTP
CVSS 9.1
CVE-2026-60647 HIGH
Oracle WebCenter Content - Denial of Service
CVSS 7.1
CVE-2026-60645 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Web Content Management
CVSS 7.2
CVE-2026-60642 HIGH
Oracle WebCenter Content - Denial of Service
CVSS 7.6
CVE-2026-60641 HIGH
Oracle WebCenter Content - Denial of Service
CVSS 7.6
CVE-2026-60632 CRITICAL
Oracle WebCenter Content 12.2.1.4.0/14.1.2.0.0: Unauth HTTP Arbitrary Data Creation, Modification, Access
CVSS 9.3
CVE-2026-60631 CRITICAL
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Arbitrary Data Creation, Deletion, and Access via HTTP
CVSS 9.3
CVE-2026-60630 MEDIUM
Oracle APEX 24.1, 24.2, and 26.1 - Authenticated Unauthorized Data Access via Installation Component
CVSS 5.5
CVE-2026-60629 HIGH
Oracle JDeveloper 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Data Exposure and Unauthorized Data Modification via HTTP
CVSS 7.5
CVE-2026-60628 LOW
JD Edwards EnterpriseOne Tools 9.2.26.3 - Unauthenticated Data Modification & Info Disclosure via Physical Access
CVSS 3.7
CVE-2026-60626 MEDIUM
JD Edwards EnterpriseOne Tools 9.2.26.3: Authenticated Critical Data Creation/Deletion/Mod via Install Security
CVSS 6.0
CVE-2026-60622 HIGH
Oracle JDeveloper 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Sensitive Data Exposure via HTTP
CVSS 7.5
CVE-2026-60620 MEDIUM
Oracle Corporation JD Edwards EnterpriseOne Configurator - Denial of Service
CVSS 6.4
CVE-2026-60619 HIGH
JD Edwards EnterpriseOne HCM 9.2 Authenticated RCE via Time Accounting & HRM Base Component
CVSS 7.5
CVE-2026-60617 MEDIUM
PeopleSoft Enterprise CS Campus Community 9.2.38 - Unauthenticated Data Modification and Information Disclosure via HTTP
CVSS 6.5
CVE-2026-60614 HIGH
Oracle Corporation PeopleSoft Enterprise CS Campus Community - Denial of Service
CVSS 7.1
CVE-2026-60613 MEDIUM
PeopleSoft Enterprise CS Student Records 9.2.38 - Remote System Takeover via Research Tracking Component
CVSS 6.6
CVE-2026-60612 MEDIUM
Oracle PeopleSoft Financial Aid 9.2.38 - Unauthorized Data Access and Modification
CVSS 6.8
CVE-2026-60608 MEDIUM
PeopleSoft Enterprise CS Financial Aid 9.2.38 - Authenticated Data Modification & Info Disclosure
CVSS 6.1
Details
Vulnerabilities 6,232