CWE-306
High likelihoodMissing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
2,844 vulnerabilities with CWE-306
CVE-2026-62447
HIGH
Oracle Trade Management 12.2.3-12.2.15 - Authenticated Remote Code Execution via Claim LOV Component
CVSS 8.8
CVE-2026-61322
HIGH
Oracle TeleSales 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-61320
HIGH
Oracle Payables 12.2.8-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-61311
HIGH
Oracle Product Hub 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-61285
HIGH
Oracle Process Manufacturing Systems < 12.2.15 - Missing Authentication for Critical Function
CVSS 7.2
CVE-2026-61267
HIGH
Oracle Hcm Configuration Workbench < 12.2.15 - Denial of Service
CVSS 7.3
CVE-2026-61247
MEDIUM
Oracle Workflow < 12.2.15 - Denial of Service
CVSS 4.8
CVE-2026-61245
CRITICAL
PeopleSoft Enterprise FIN Manufacturing Brazil 9.1 - Unauthenticated Remote Code Execution via Integration Component
CVSS 9.8
CVE-2026-61243
HIGH
PeopleSoft Enterprise FIN Common Objects Argentina 9.1 - Authenticated Remote Code Execution via Staffing Component
CVSS 8.8
CVE-2026-61239
CRITICAL
Oracle Corporation PeopleSoft Enterprise Fin Common Objects Argentina - Denial of Service
CVSS 9.9
CVE-2026-61233
CRITICAL
PeopleSoft Enterprise FIN Common Objects Brazil 9.1 - Unauthenticated Remote Code Execution via Integration Component
CVSS 9.8
CVE-2026-61225
HIGH
Oracle Communications Converged Application Server 8.2 and 8.3 - Unauthenticated Remote Takeover via TCP/IP
CVSS 8.1
CVE-2026-61203
CRITICAL
Oracle Corporation PeopleSoft Enterprise Fin Expenses - Denial of Service
CVSS 9.4
CVE-2026-61201
CRITICAL
PeopleSoft Enterprise CRM Common Objects 9.2.23 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.0
CVE-2026-61196
CRITICAL
Oracle Identity Manager 12.2.1.4.0 and 14.1.2.1.0 - Unauthenticated Remote Takeover via OIM Legacy UI
CVSS 9.8
CVE-2026-61188
HIGH
Oracle Agile Product Lifecycle Management for Process 6.2.4 - Authenticated Remote Takeover via Installation Component
CVSS 7.5
CVE-2026-61186
CRITICAL
Oracle Agile Engineering Data Management - Denial of Service
CVSS 9.4
CVE-2026-61183
CRITICAL
Oracle Agile Product Lifecycle Management for Process 6.2.4 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-61180
HIGH
Oracle Agile PLM for Process 6.2.4: Auth RCE via Product Quality Management Component
CVSS 8.8
CVE-2026-61179
HIGH
Oracle Agile PLM for Process 6.2.4: Authenticated Remote Takeover via PQM Component
CVSS 8.8
CVE-2026-61178
CRITICAL
Oracle Agile PLM for Process 6.2.4 - Unauth RCE via Installation Component
CVSS 9.8
CVE-2026-61176
MEDIUM
Oracle Product Lifecycle Analytics - Denial of Service
CVSS 6.7
CVE-2026-61175
CRITICAL
Oracle Product Lifecycle Analytics - Denial of Service
CVSS 9.3
CVE-2026-61171
CRITICAL
Oracle Agile PLM 9.3.6 - Unauthenticated Critical Data Access and Modification via HTTP
CVSS 9.1
CVE-2026-61170
HIGH
Oracle Agile PLM 9.3.6 - Unauthenticated Remote Code Execution via HTTP
CVSS 8.1
Details
Vulnerabilities
2,844
Exploit Likelihood
High