CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,847 vulnerabilities with CWE-306
CVE-2026-46940 HIGH
Oracle Cost Management 12.2.3-12.2.15 - Authenticated Remote Code Execution in Cost Planning
CVSS 8.8
CVE-2026-46937 HIGH
Oracle iSetup 12.2.3-12.2.15 - Authenticated Remote Code Execution in General Ledger Update Transform
CVSS 8.8
CVE-2026-46935 HIGH
Oracle Complex Maintenance, Repair and Overhaul 12.2.3-12.2.15 - Remote Code Execution via HTTP
CVSS 7.5
CVE-2026-46934 HIGH
Oracle Complex Maintenance, Repair and Overhaul 12.2.3-12.2.15 - Remote Code Execution via HTTP
CVSS 7.5
CVE-2026-46933 CRITICAL
Oracle Applications Manager 12.2.3-12.2.15 - Authenticated Remote Code Execution via HTTP
CVSS 9.9
CVE-2026-46929 HIGH
Oracle Cost Management 12.2.3-12.2.15 - Authenticated Remote Code Execution in Cost Planning
CVSS 8.8
CVE-2026-46928 HIGH
Oracle Spares Management 12.2.3-12.2.15 - Authenticated Remote Code Execution via HTTPS
CVSS 8.8
CVE-2026-46927 HIGH
Oracle Receivables 12.2.3-12.2.15 - Unauthenticated Remote Code Execution via SOAP
CVSS 8.1
CVE-2026-46922 HIGH
Oracle HR Intelligence 12.2.3-12.2.15 - Authenticated Remote Code Execution
CVSS 7.2
CVE-2026-46921 HIGH
Siebel CRM Cloud Applications 17.0-26.5 - Authenticated Remote Code Execution in Siebel Cloud Manager
CVSS 8.8
CVE-2026-46920 HIGH
Siebel CRM Cloud Applications 17.0-26.5 - Unauthenticated Remote Code Execution via HTTP
CVSS 8.1
CVE-2026-46919 CRITICAL
Oracle Siebel CRM Cloud Applications 17.0-26.5 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-46916 HIGH
Oracle Process Manufacturing 12.2.3-12.2.15 - Authenticated RCE in Quality Management
CVSS 8.8
CVE-2026-46912 CRITICAL
JD Edwards EnterpriseOne Tools 9.2.0.0-9.2.26.2 - Unauthenticated Unauthorized Data Access via Web Runtime Security
CVSS 9.3
CVE-2026-46910 CRITICAL
Oracle Corporation JD Edwards EnterpriseOne Tools < 9.2.26.2 - Denial of Service
CVSS 9.1
CVE-2026-46909 CRITICAL
JD Edwards EnterpriseOne Tools 9.2.0.0-9.2.26.2 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-46905 CRITICAL
JD Edwards EnterpriseOne Tools 9.2.0.0-9.2.26.2 - Unauthenticated Remote Code Execution via Web Runtime Security
CVSS 9.8
CVE-2026-46904 CRITICAL
JD Edwards EnterpriseOne Tools 9.2.0.0-9.2.26.2 - Unauthenticated Remote Code Execution via JDENET
CVSS 9.8
CVE-2026-46903 HIGH
JD Edwards EnterpriseOne Tools 9.2.0.0-9.2.26.2 - Authenticated Remote Code Execution
CVSS 8.8
CVE-2026-46902 CRITICAL
Oracle Enterprise Command Center Framework V15 and V16 - Unauthenticated Remote Code Execution via HTTPS
CVSS 9.8
CVE-2026-46892 CRITICAL
JD Edwards EnterpriseOne Human Resources Management 9.2 - Unauthenticated Data Manipulation and Access via HTTP
CVSS 9.1
CVE-2026-46890 CRITICAL
Oracle Siebel Apps - Marketing 17.0-26.5 - Unauthenticated Remote Code Execution
CVSS 9.8
CVE-2026-46879 CRITICAL
JD Edwards EnterpriseOne Tools 9.2.0.0-9.2.26.2 - Unauthenticated Remote Code Execution via JDENET
CVSS 9.8
CVE-2026-46846 CRITICAL
Oracle WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution
CVSS 10.0
CVE-2026-46845 CRITICAL
Oracle WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTPS
CVSS 9.8
Details
Vulnerabilities 2,847
Exploit Likelihood High