CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

6,227 vulnerabilities with CWE-284
CVE-2026-61252 MEDIUM
Oracle Hrms (Hong Kong) < 12.2.15 - Improper Access Control
CVSS 5.4
CVE-2026-61250 MEDIUM
Oracle Payroll < 12.2.15 - Improper Access Control
CVSS 6.5
CVE-2026-61245 CRITICAL
PeopleSoft Enterprise FIN Manufacturing Brazil 9.1 - Unauthenticated Remote Code Execution via Integration Component
CVSS 9.8
CVE-2026-61244 CRITICAL
PeopleSoft Enterprise FIN Manufacturing Argentina 9.1 - Unauthenticated Data Creation/Modification/Access via HTTP
CVSS 9.1
CVE-2026-61243 HIGH
PeopleSoft Enterprise FIN Common Objects Argentina 9.1 - Authenticated Remote Code Execution via Staffing Component
CVSS 8.8
CVE-2026-61242 CRITICAL
PeopleSoft Enterprise FIN Common Objects Argentina 9.1 - Authenticated Remote Code Execution via Staffing Component
CVSS 9.9
CVE-2026-61240 HIGH
PeopleSoft Enterprise FIN Common Objects Argentina 9.1 - Unauthenticated Data Access/Modification via Physical Access
CVSS 8.2
CVE-2026-61239 CRITICAL
Oracle Corporation PeopleSoft Enterprise Fin Common Objects Argentina - Denial of Service
CVSS 9.9
CVE-2026-61238 CRITICAL
PeopleSoft Enterprise FIN Common Objects Argentina 9.1 - Unauthenticated Data Creation/Modification/Access via HTTP
CVSS 9.1
CVE-2026-61237 CRITICAL
Oracle Corporation PeopleSoft Enterprise Fin Common Objects Argentina - Denial of Service
CVSS 9.9
CVE-2026-61236 HIGH
PeopleSoft Enterprise FIN Common Objects Brazil 9.1 - Unauthenticated Unauthorized Data Access via HTTP
CVSS 7.5
CVE-2026-61235 CRITICAL
PeopleSoft Enterprise HCM Global Payroll Switzerland 9.2 - Authenticated Remote System Takeover via HTTP
CVSS 9.1
CVE-2026-61234 HIGH
PeopleSoft Enterprise FIN Common Objects Brazil 9.1 - Unauthenticated Data Creation, Deletion, and Access via HTTP
CVSS 7.4
CVE-2026-61233 CRITICAL
PeopleSoft Enterprise FIN Common Objects Brazil 9.1 - Unauthenticated Remote Code Execution via Integration Component
CVSS 9.8
CVE-2026-61232 HIGH
PeopleSoft Enterprise FIN Common Objects Brazil 9.1 - Unauthenticated Unauthorized Data Access via HTTP
CVSS 7.5
CVE-2026-61226 HIGH
Oracle Communications Converged Application Server 8.3 - Authenticated Remote Takeover via RTP Proxy
CVSS 7.5
CVE-2026-61224 HIGH
Oracle Communications Converged Application Server 8.3 - Authenticated Remote Takeover via TLS
CVSS 8.0
CVE-2026-61223 CRITICAL
Oracle Communications Converged Application Server 8.2-8.3 - Unauthenticated Remote Code Execution via TCP/IP
CVSS 9.0
CVE-2026-61221 MEDIUM
Oracle Item Master < 12.2.15 - Improper Access Control
CVSS 5.4
CVE-2026-61220 MEDIUM
Oracle Banking Origination - Improper Access Control
CVSS 6.1
CVE-2026-61218 HIGH
Oracle E-Business Suite 12.2.3-12.2.15 SES: Authenticated Data Modification & Unauthorized Access via Search Engine
CVSS 8.1
CVE-2026-61217 MEDIUM
Oracle Security Service - Improper Access Control
CVSS 6.4
CVE-2026-61216 MEDIUM
Oracle Payroll < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-61211 CRITICAL
Oracle Database Server 19.3-19.31 and 23.4.0-23.26.2 - Authenticated Remote Takeover via RDBMS DBMS_CLOUD Component
CVSS 9.9
CVE-2026-61210 HIGH
PeopleSoft Enterprise SCM Manufacturing 9.2 - Unauth HTTPS Data Creation, Modification, Deletion & Access
CVSS 7.4
Details
Vulnerabilities 6,227