CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,844 vulnerabilities with CWE-306
CVE-2026-61168 HIGH
Oracle Agile PLM 9.3.6 - Authenticated Remote Code Execution via Security Component
CVSS 8.8
CVE-2026-61167 CRITICAL
Oracle Agile PLM 9.3.6 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-61163 HIGH
Oracle Commerce Guided Search and Experience Manager 11.4.0 - Unauthenticated Remote Code Execution via Forge Component
CVSS 8.1
CVE-2026-61161 CRITICAL
Oracle Commerce Guided Search/Experience Manager 11.4.0 - Unauth RCE via Endeca Controller
CVSS 9.8
CVE-2026-61158 HIGH
Oracle Commerce Guided Search and Experience Manager 11.4.0 - Unauthenticated Unauthorized Data Access via RMI
CVSS 7.5
CVE-2026-61155 CRITICAL
Oracle Commerce Guided Search Platform Services - Denial of Service
CVSS 9.1
CVE-2026-61154 CRITICAL
Oracle Commerce Guided Search Platform Services 11.4.0 - Unauthenticated Remote Code Execution via Forge Component
CVSS 9.8
CVE-2026-61149 HIGH
Oracle Commerce Guided Search and Experience Manager 11.4.0 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-61146 CRITICAL
Oracle Commerce Guided Search/Experience Manager 11.4.0 - Auth RCE via Content Acquisition System
CVSS 9.9
CVE-2026-61145 CRITICAL
Oracle Commerce Guided Search/Experience Manager 11.4.0 - Unauth RCE via Content Acquisition System
CVSS 9.8
CVE-2026-61141 HIGH
Oracle Advanced Benefits 12.2.7-12.2.15 - Authenticated Remote Takeover via Affordable Care Act Component
CVSS 7.5
CVE-2026-61140 CRITICAL
Oracle WebCenter Sites 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-61137 HIGH
Oracle Commerce Platform 11.4.0 - Unauthenticated Remote Code Execution via Dynamo Application Framework
CVSS 8.1
CVE-2026-61135 HIGH
Oracle Commerce 11.4.0: Unauthenticated Data Creation/Deletion & Unauthorized Access via Dynamo Framework
CVSS 7.4
CVE-2026-61131 CRITICAL
Oracle Commerce Platform 11.4.0 - Unauthenticated Remote Code Execution via Dynamo Application Framework
CVSS 9.8
CVE-2026-61130 CRITICAL
Oracle Commerce Platform - Denial of Service
CVSS 9.1
CVE-2026-61129 CRITICAL
Oracle Commerce Platform 11.4.0 - Unauthenticated Remote Code Execution via ATG Portals
CVSS 9.8
CVE-2026-61127 HIGH
Oracle Communications Service Catalog/Design 8.0.0.7.0-8.3.0.2.0 Auth RCE via Solution Designer
CVSS 8.8
CVE-2026-61121 HIGH
Oracle HRMS (UK) 12.2.8-12.2.15 - Authenticated Remote Code Execution via UK Payroll Component
CVSS 8.8
CVE-2026-61110 HIGH
Oracle Applications DBA 12.2.3-12.2.15 - Authenticated Remote Code Execution via ADPatch Component
CVSS 8.8
CVE-2026-61106 HIGH
Oracle GoldenGate 23.4-23.26.2 - Unauthenticated Remote Code Execution via Config Service Executable
CVSS 8.1
CVE-2026-61100 CRITICAL
Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via Client Bundle
CVSS 9.8
CVE-2026-61099 HIGH
Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Client Bundle
CVSS 8.8
CVE-2026-61098 HIGH
Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-61094 HIGH
MySQL 8.0.0-8.0.47, 8.4.0-8.4.1, 9.7.0-9.7.1 Authenticated Remote Takeover via Replication
CVSS 7.2
Details
Vulnerabilities 2,844
Exploit Likelihood High