CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,844 vulnerabilities with CWE-306
CVE-2026-60596 LOW
PeopleSoft Enterprise FIN eSettlements 9.2 - Authenticated Information Disclosure via Local Access
CVSS 2.3
CVE-2026-60595 MEDIUM
PeopleSoft Enterprise FIN Pay/Bill Mgmt 9.2: Authenticated Unauthorized Data Access
CVSS 5.5
CVE-2026-60586 HIGH
MySQL Connectors 9.7.0-9.7.1 - Authenticated Unauthorized Data Access via Connector/J
CVSS 7.7
CVE-2026-60583 HIGH
Oracle Transportation Management 6.5.3 - Authenticated Remote Takeover via Install Component
CVSS 8.8
CVE-2026-60580 HIGH
Oracle Enterprise Command Center Framework V16 - Unauthenticated Remote Code Execution via Physical Network Access
CVSS 8.8
CVE-2026-60574 MEDIUM
Oracle Content Manager < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-60569 MEDIUM
MySQL Cluster 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1 - Unauthenticated Unauthorized Data Access via NDB Operator
CVSS 5.1
CVE-2026-60557 MEDIUM
Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Sensitive Data Exposure via HTTP with User Interaction
CVSS 6.5
CVE-2026-60551 CRITICAL
Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-60549 HIGH
Oracle Managed File Transfer 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via MFT Runtime Server
CVSS 8.8
CVE-2026-60545 HIGH
Oracle Managed File Transfer 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60544 HIGH
Oracle Soa Suite - Denial of Service
CVSS 8.2
CVE-2026-60543 HIGH
Oracle SOA Suite 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via B2B Engine
CVSS 8.1
CVE-2026-60539 HIGH
Oracle SOA Suite 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution in Integration Business Insight
CVSS 8.8
CVE-2026-60538 CRITICAL
Oracle SOA Suite 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via Enterprise Scheduling System
CVSS 9.8
CVE-2026-60537 CRITICAL
Oracle Managed File Transfer 12.2.1.4.0 and 14.1.2.0.0 - Authenticated Remote Takeover via HTTP
CVSS 9.9
CVE-2026-60535 CRITICAL
Oracle Identity Manager Connector 12.2.1.4.0 and 14.1.2.1.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-60531 CRITICAL
Oracle Identity Manager Connector 12.2.1.4.0 and 14.1.2.1.0 - Authenticated Remote Code Execution via HTTP
CVSS 9.9
CVE-2026-60499 HIGH
JD Edwards EnterpriseOne Solution Advisor 9.2 - Authenticated Remote Code Execution via Solution Advisor Component
CVSS 8.8
CVE-2026-60498 HIGH
JD Edwards EnterpriseOne Human Resources Management 9.2 - Authenticated Remote Takeover via JDENET
CVSS 7.5
CVE-2026-60497 HIGH
JD Edwards EnterpriseOne CRM Foundation 9.2 - Authenticated Remote Takeover via JDENET
CVSS 7.5
CVE-2026-60496 HIGH
JD Edwards EnterpriseOne Advanced Pricing - Procurement 9.2 - Authenticated Remote Code Execution via JDENET
CVSS 7.5
CVE-2026-60495 HIGH
Oracle JD Edwards EnterpriseOne Requirements Planning 9.2 - Authenticated Remote Code Execution via JDENET
CVSS 7.5
CVE-2026-60493 HIGH
JD Edwards EnterpriseOne Human Resources Management 9.2 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-60489 HIGH
JD Edwards EnterpriseOne CRM Foundation 9.2 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
Details
Vulnerabilities 2,844
Exploit Likelihood High