CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,844 vulnerabilities with CWE-306
CVE-2026-62447 HIGH
Oracle Trade Management 12.2.3-12.2.15 - Authenticated Remote Code Execution via Claim LOV Component
CVSS 8.8
CVE-2026-61322 HIGH
Oracle TeleSales 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-61320 HIGH
Oracle Payables 12.2.8-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-61311 HIGH
Oracle Product Hub 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-61285 HIGH
Oracle Process Manufacturing Systems < 12.2.15 - Missing Authentication for Critical Function
CVSS 7.2
CVE-2026-61267 HIGH
Oracle Hcm Configuration Workbench < 12.2.15 - Denial of Service
CVSS 7.3
CVE-2026-61247 MEDIUM
Oracle Workflow < 12.2.15 - Denial of Service
CVSS 4.8
CVE-2026-61245 CRITICAL
PeopleSoft Enterprise FIN Manufacturing Brazil 9.1 - Unauthenticated Remote Code Execution via Integration Component
CVSS 9.8
CVE-2026-61243 HIGH
PeopleSoft Enterprise FIN Common Objects Argentina 9.1 - Authenticated Remote Code Execution via Staffing Component
CVSS 8.8
CVE-2026-61239 CRITICAL
Oracle Corporation PeopleSoft Enterprise Fin Common Objects Argentina - Denial of Service
CVSS 9.9
CVE-2026-61233 CRITICAL
PeopleSoft Enterprise FIN Common Objects Brazil 9.1 - Unauthenticated Remote Code Execution via Integration Component
CVSS 9.8
CVE-2026-61225 HIGH
Oracle Communications Converged Application Server 8.2 and 8.3 - Unauthenticated Remote Takeover via TCP/IP
CVSS 8.1
CVE-2026-61203 CRITICAL
Oracle Corporation PeopleSoft Enterprise Fin Expenses - Denial of Service
CVSS 9.4
CVE-2026-61201 CRITICAL
PeopleSoft Enterprise CRM Common Objects 9.2.23 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.0
CVE-2026-61196 CRITICAL
Oracle Identity Manager 12.2.1.4.0 and 14.1.2.1.0 - Unauthenticated Remote Takeover via OIM Legacy UI
CVSS 9.8
CVE-2026-61188 HIGH
Oracle Agile Product Lifecycle Management for Process 6.2.4 - Authenticated Remote Takeover via Installation Component
CVSS 7.5
CVE-2026-61186 CRITICAL
Oracle Agile Engineering Data Management - Denial of Service
CVSS 9.4
CVE-2026-61183 CRITICAL
Oracle Agile Product Lifecycle Management for Process 6.2.4 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-61180 HIGH
Oracle Agile PLM for Process 6.2.4: Auth RCE via Product Quality Management Component
CVSS 8.8
CVE-2026-61179 HIGH
Oracle Agile PLM for Process 6.2.4: Authenticated Remote Takeover via PQM Component
CVSS 8.8
CVE-2026-61178 CRITICAL
Oracle Agile PLM for Process 6.2.4 - Unauth RCE via Installation Component
CVSS 9.8
CVE-2026-61176 MEDIUM
Oracle Product Lifecycle Analytics - Denial of Service
CVSS 6.7
CVE-2026-61175 CRITICAL
Oracle Product Lifecycle Analytics - Denial of Service
CVSS 9.3
CVE-2026-61171 CRITICAL
Oracle Agile PLM 9.3.6 - Unauthenticated Critical Data Access and Modification via HTTP
CVSS 9.1
CVE-2026-61170 HIGH
Oracle Agile PLM 9.3.6 - Unauthenticated Remote Code Execution via HTTP
CVSS 8.1
Details
Vulnerabilities 2,844
Exploit Likelihood High