CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,847 vulnerabilities with CWE-306
CVE-2026-46813 CRITICAL
Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-46807 CRITICAL
Oracle Identity Manager 12.2.1.4.0 and 14.1.2.1.0 - Unauthenticated Remote Code Execution via T3/IIOP
CVSS 9.8
CVE-2026-46803 CRITICAL
Oracle WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 10.0
CVE-2026-46801 CRITICAL
Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-46800 CRITICAL
Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 10.0
CVE-2026-46799 CRITICAL
Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-46798 CRITICAL
Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 10.0
CVE-2026-46789 CRITICAL
Oracle WebCenter Content 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.6
CVE-2026-46783 CRITICAL
Oracle WebCenter Content: Imaging 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-46781 CRITICAL
Oracle WebCenter Enterprise Capture 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via RMI
CVSS 10.0
CVE-2026-46780 HIGH
Oracle WebCenter Content: Imaging 12.2.1.4.0 and 14.1.2.0.0 - Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-46778 CRITICAL
Oracle WebCenter Enterprise Capture 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via RMI
CVSS 10.0
CVE-2026-35304 CRITICAL
Oracle Coherence 12.2.1.4.0 14.1.1.0.0 14.1.2.0.0 15.1.1.0.0 - Unauthenticated Remote Code Execution via HTTPS
CVSS 9.8
CVE-2026-35303 HIGH
Oracle WebLogic Server 12.2.1.4.0 and 14.1.1.0.0 - Remote Code Execution via Console
CVSS 8.8
CVE-2026-35301 CRITICAL
Oracle WebLogic Server 12.2.1.4.0 and 14.1.1.0.0 - Unauthenticated Remote Code Execution via Console
CVSS 10.0
CVE-2026-35299 HIGH
Oracle WebLogic Server 12.2.1.4.0 and 14.1.1.0.0 - Remote Code Execution via Console
CVSS 8.8
CVE-2026-35296 CRITICAL
Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-35295 HIGH
Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 - Authenticated Remote Code Execution
CVSS 7.5
CVE-2026-35293 CRITICAL
Oracle WebCenter Sites 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-35292 CRITICAL
Oracle WebLogic Server 14.1.2.0.0 and 15.1.1.0.0 - Unauthenticated Remote Code Execution via Console
CVSS 10.0
CVE-2026-35289 HIGH
PeopleSoft Enterprise PT PeopleTools 8.61-8.62 - Unauthenticated Remote Code Execution via Deployment Package
CVSS 8.1
CVE-2026-35286 CRITICAL
Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-35279 HIGH
PeopleSoft Enterprise PT PeopleTools 8.61-8.62 - Unauthenticated Remote Code Execution in Performance Monitor
CVSS 8.1
CVE-2026-35278 CRITICAL
PeopleSoft Enterprise PT PeopleTools 8.61-8.62 - Unauthenticated Remote Code Execution in Performance Monitor
CVSS 9.8
CVE-2026-35276 HIGH
PeopleSoft Enterprise PT PeopleTools 8.61-8.62 - Unauthenticated Remote Code Execution via HTTP
CVSS 8.1
Details
Vulnerabilities 2,847
Exploit Likelihood High