CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,845 vulnerabilities with CWE-306
CVE-2026-60291 CRITICAL
Oracle WebLogic Server 12.2.1.4.0/14.1.1.0.0/14.1.2.0.0/15.1.1.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-60290 CRITICAL
Oracle Coherence 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-60289 CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-60288 CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 9.8
CVE-2026-60287 CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 9.8
CVE-2026-60286 CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-60285 CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 9.8
CVE-2026-60280 CRITICAL
Oracle Coherence 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 - Unauthenticated Remote Code Execution via HTTP/2
CVSS 9.8
CVE-2026-60278 CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-60277 HIGH
Oracle Coherence 12.2.1.4.0/14.1.1.0.0/14.1.2.0.0/15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 8.1
CVE-2026-60276 CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via HTTPS
CVSS 9.8
CVE-2026-60275 CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-60274 CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 9.8
CVE-2026-60273 HIGH
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 8.1
CVE-2026-60272 CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-60263 HIGH
Oracle Coherence 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Unauthorized Data Access via TCP
CVSS 7.5
CVE-2026-60262 CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 9.8
CVE-2026-60259 CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-60258 CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 9.8
CVE-2026-60257 CRITICAL
Oracle Coherence 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 9.8
CVE-2026-60256 CRITICAL
Oracle Coherence 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 9.8
CVE-2026-60255 HIGH
Oracle Coherence - Denial of Service
CVSS 8.2
CVE-2026-60254 CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 9.8
CVE-2026-60253 CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 9.8
CVE-2026-60251 CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 9.8
Details
Vulnerabilities 2,845
Exploit Likelihood High