CWE-287

High likelihood

Improper Authentication

Parent: CWE-284 - Improper Access Control

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

4,568 vulnerabilities with CWE-287
CVE-2026-61180 HIGH
Oracle Agile PLM for Process 6.2.4: Auth RCE via Product Quality Management Component
CVSS 8.8
CVE-2026-61179 HIGH
Oracle Agile PLM for Process 6.2.4: Authenticated Remote Takeover via PQM Component
CVSS 8.8
CVE-2026-61178 CRITICAL
Oracle Agile PLM for Process 6.2.4 - Unauth RCE via Installation Component
CVSS 9.8
CVE-2026-61168 HIGH
Oracle Agile PLM 9.3.6 - Authenticated Remote Code Execution via Security Component
CVSS 8.8
CVE-2026-61163 HIGH
Oracle Commerce Guided Search and Experience Manager 11.4.0 - Unauthenticated Remote Code Execution via Forge Component
CVSS 8.1
CVE-2026-61154 CRITICAL
Oracle Commerce Guided Search Platform Services 11.4.0 - Unauthenticated Remote Code Execution via Forge Component
CVSS 9.8
CVE-2026-61149 HIGH
Oracle Commerce Guided Search and Experience Manager 11.4.0 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-61137 HIGH
Oracle Commerce Platform 11.4.0 - Unauthenticated Remote Code Execution via Dynamo Application Framework
CVSS 8.1
CVE-2026-61131 CRITICAL
Oracle Commerce Platform 11.4.0 - Unauthenticated Remote Code Execution via Dynamo Application Framework
CVSS 9.8
CVE-2026-61129 CRITICAL
Oracle Commerce Platform 11.4.0 - Unauthenticated Remote Code Execution via ATG Portals
CVSS 9.8
CVE-2026-61127 HIGH
Oracle Communications Service Catalog/Design 8.0.0.7.0-8.3.0.2.0 Auth RCE via Solution Designer
CVSS 8.8
CVE-2026-61121 HIGH
Oracle HRMS (UK) 12.2.8-12.2.15 - Authenticated Remote Code Execution via UK Payroll Component
CVSS 8.8
CVE-2026-61110 HIGH
Oracle Applications DBA 12.2.3-12.2.15 - Authenticated Remote Code Execution via ADPatch Component
CVSS 8.8
CVE-2026-61099 HIGH
Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Client Bundle
CVSS 8.8
CVE-2026-61098 HIGH
Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-61074 HIGH
PeopleSoft Enterprise FIN Common Objects Brazil 9.1 - Unauthenticated Remote Code Execution via eProcurement Component
CVSS 8.1
CVE-2026-61067 HIGH
Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0 - Authenticated Remote Takeover via Physical Network Access
CVSS 8.0
CVE-2026-61065 CRITICAL
Oracle Access Manager 12.2.1.4.0 and 14.1.2.1.0 - Unauthenticated Remote Takeover via Authentication Engine
CVSS 9.8
CVE-2026-61049 HIGH
Oracle Production Scheduling 12.2.3-12.2.15 Unauth RCE via Physical Network Access & User Interaction
CVSS 7.1
CVE-2026-61010 HIGH
Oracle Process Manufacturing Systems 12.2.3-12.2.15 - Authenticated Remote System Takeover via HTTP
CVSS 8.8
CVE-2026-60989 HIGH
Oracle Advanced Collections 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60952 HIGH
Oracle Transportation Execution 12.2.3-12.2.15 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-60932 HIGH
Oracle Labor Distribution 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60931 HIGH
Oracle Public Sector Financials 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.5
CVE-2026-60927 HIGH
Oracle Public Sector Financials 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.5
Details
Vulnerabilities 4,568
Exploit Likelihood High