CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,845 vulnerabilities with CWE-306
CVE-2026-60489 HIGH
JD Edwards EnterpriseOne CRM Foundation 9.2 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-60463 CRITICAL
Oracle WebCenter Content: Imaging 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via T3/IIOP
CVSS 9.8
CVE-2026-60462 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 8.1
CVE-2026-60461 CRITICAL
Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via T3/IIOP Protocol
CVSS 9.9
CVE-2026-60460 CRITICAL
Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via T3/IIOP Protocol
CVSS 9.8
CVE-2026-60458 CRITICAL
Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via T3/IIOP Protocol
CVSS 9.9
CVE-2026-60450 HIGH
Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via Content Server
CVSS 8.1
CVE-2026-60446 CRITICAL
Oracle WebCenter Enterprise Capture 12.2.1.4.0/14.1.2.0.0 - Unauth RCE via T3/IIOP
CVSS 9.8
CVE-2026-60442 CRITICAL
Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via T3 or IIOP Protocol
CVSS 9.8
CVE-2026-60441 CRITICAL
Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via T3/IIOP Protocol
CVSS 9.8
CVE-2026-60435 CRITICAL
Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via Content Server
CVSS 9.8
CVE-2026-60424 CRITICAL
Oracle Unified Directory 12.2.1.4.0 and 14.1.2.1.0 - Unauthenticated Remote Takeover via LDAP
CVSS 9.0
CVE-2026-60417 HIGH
Oracle Unified Directory 12.2.1.4.0, 14.1.2.1.0 - Unauthenticated Remote Takeover via LDAP
CVSS 8.1
CVE-2026-60398 HIGH
Oracle GoldenGate 19.1.0.0.0-19.30.0.0, 21.3-21.21, 23.4-23.26.1 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-60396 HIGH
Oracle GoldenGate 21.3-21.21 and 23.4-23.26.1 - Authenticated Remote Code Execution via Distribution Server Executable
CVSS 7.2
CVE-2026-60389 CRITICAL
Oracle Service Delivery Platform 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via Messaging Enabler
CVSS 10.0
CVE-2026-60388 CRITICAL
Oracle Service Delivery Platform 12.2.1.4.0/14.1.2.0.0 Unauthenticated RCE via T3/IIOP
CVSS 9.8
CVE-2026-60387 CRITICAL
Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via T3 or IIOP Protocol
CVSS 9.8
CVE-2026-60386 CRITICAL
Oracle Service Delivery Platform 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via Messaging Enabler
CVSS 9.8
CVE-2026-60385 CRITICAL
Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via T3 or IIOP Protocol
CVSS 9.8
CVE-2026-60384 CRITICAL
Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via T3 or IIOP Protocol
CVSS 9.8
CVE-2026-60380 CRITICAL
Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via Messaging Enabler
CVSS 9.8
CVE-2026-60379 CRITICAL
Oracle Service Delivery Platform 12.2.1.4.0/14.1.2.0.0 Unauth RCE via SOAP Messaging Enabler
CVSS 10.0
CVE-2026-60378 CRITICAL
Oracle Service Delivery Platform 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via Messaging Enabler
CVSS 9.8
CVE-2026-60376 CRITICAL
Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via T3 or IIOP Protocol
CVSS 9.8
Details
Vulnerabilities 2,845
Exploit Likelihood High