CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,844 vulnerabilities with CWE-306
CVE-2026-61092 HIGH
Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 8.1
CVE-2026-61074 HIGH
PeopleSoft Enterprise FIN Common Objects Brazil 9.1 - Unauthenticated Remote Code Execution via eProcurement Component
CVSS 8.1
CVE-2026-61010 HIGH
Oracle Process Manufacturing Systems 12.2.3-12.2.15 - Authenticated Remote System Takeover via HTTP
CVSS 8.8
CVE-2026-60999 CRITICAL
Oracle Data Integrator 14.1.2.0.0 - Unauthenticated Remote Code Execution via Rest Service
CVSS 9.8
CVE-2026-60989 HIGH
Oracle Advanced Collections 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60988 HIGH
Oracle Project Portfolio Analysis 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.5
CVE-2026-60979 HIGH
Oracle Scripting 12.2.3-12.2.15 - Unauthenticated Remote Code Execution via HTTP
CVSS 8.1
CVE-2026-60952 HIGH
Oracle Transportation Execution 12.2.3-12.2.15 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-60932 HIGH
Oracle Labor Distribution 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60931 HIGH
Oracle Public Sector Financials 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.5
CVE-2026-60927 HIGH
Oracle Public Sector Financials 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.5
CVE-2026-60925 HIGH
Oracle Public Sector Payroll 12.2.4-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.2
CVE-2026-60924 HIGH
Oracle Public Sector Payroll 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60920 HIGH
Oracle Customer Care 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60918 HIGH
Oracle Shipping Execution 12.2.12-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.2
CVE-2026-60908 HIGH
Oracle Installed Base 12.2.3-12.2.15 - Authenticated Data Access and Modification via Create Item Instance Component
CVSS 7.1
CVE-2026-60901 HIGH
Oracle Project Intelligence 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60898 HIGH
Oracle Warehouse Management 12.2.3-12.2.15 - Authenticated Remote Code Execution via Internal Operations Component
CVSS 8.8
CVE-2026-60897 HIGH
Oracle Payroll 12.2.3-12.2.15 - Authenticated Remote Code Execution via Internal Operations Component
CVSS 8.8
CVE-2026-60894 HIGH
Oracle Payroll 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.5
CVE-2026-60890 HIGH
Oracle Payroll 12.2.3-12.2.15 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-60880 CRITICAL
Oracle Work in Process 12.2.3-12.2.15 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-60872 HIGH
Oracle Order Management 12.2.3-12.2.15 - Authenticated Remote Code Execution via Product Diagnostic Tools
CVSS 8.8
CVE-2026-60863 HIGH
Oracle Advanced Pricing 12.2.3-12.2.15 - Authenticated Remote Takeover via Pricing Installation Component
CVSS 8.8
CVE-2026-60859 HIGH
Oracle Quoting 12.2.3-12.2.15 - Authenticated Remote Code Execution via Internal Operations Component
CVSS 7.5
Details
Vulnerabilities 2,844
Exploit Likelihood High