CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,845 vulnerabilities with CWE-306
CVE-2026-60375 CRITICAL
Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via T3 or IIOP Protocol
CVSS 9.8
CVE-2026-60374 CRITICAL
Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via T3/IIOP Protocol
CVSS 9.8
CVE-2026-60365 CRITICAL
Oracle Weblogic Server Proxy Plug-in 15.1.1.0.0 - Unauthenticated Arbitrary Data Creation, Deletion and Access via HTTP
CVSS 10.0
CVE-2026-60362 CRITICAL
Oracle Unified Directory 12.2.1.4.0 and 14.1.2.1.0 - Unauthenticated Remote Takeover via LDAP
CVSS 9.8
CVE-2026-60361 CRITICAL
Oracle Unified Directory 12.2.1.4.0, 14.1.2.1.0 - Authenticated Remote Code Execution via LDAP with Scope Change
CVSS 9.9
CVE-2026-60360 CRITICAL
Oracle Unified Directory 12.2.1.4.0 and 14.1.2.1.0 - Unauthenticated Remote Code Execution via LDAP
CVSS 10.0
CVE-2026-60359 HIGH
Oracle Unified Directory 12.2.1.4.0 and 14.1.2.1.0 - Unauthenticated Unauthorized Data Access via HTTP
CVSS 8.6
CVE-2026-60356 HIGH
Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0 - Unauthenticated Unauthorized Data Access via Authentication Engine
CVSS 8.6
CVE-2026-60355 CRITICAL
Oracle Access Manager 12.2.1.4.0 and 14.1.2.1.0 - Unauthenticated Remote Takeover via Authentication Engine
CVSS 9.8
CVE-2026-60335 HIGH
Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0 - Authenticated Remote Code Execution via Content Server
CVSS 7.2
CVE-2026-60334 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Content Server
CVSS 8.8
CVE-2026-60329 CRITICAL
Oracle Identity Manager 12.2.1.4.0, 14.1.2.1.0 - Unauthenticated Remote Code Execution via T3/IIOP Protocol
CVSS 9.8
CVE-2026-60322 MEDIUM
Oracle Apps Manager 12.2.3-12.2.15: Unauthenticated Data Mod & Info Disclosure via Diagnostics
CVSS 6.5
CVE-2026-60313 HIGH
Oracle WebLogic Server 12.2.1.4.0/14.1.1.0.0/14.1.2.0.0/15.1.1.0.0 - Authenticated Remote Code Execution via RMI
CVSS 8.8
CVE-2026-60312 HIGH
Oracle WebLogic Server 12.2.1.4.0/14.1.1-2.0.0/15.1.1.0.0 Unauth RCE via T3/IIOP
CVSS 8.1
CVE-2026-60308 CRITICAL
Oracle Coherence 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-60306 CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 9.8
CVE-2026-60302 CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 9.8
CVE-2026-60300 CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 9.8
CVE-2026-60299 CRITICAL
Oracle Coherence 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 9.8
CVE-2026-60298 CRITICAL
Oracle Coherence 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 9.8
CVE-2026-60297 CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 9.8
CVE-2026-60296 CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 9.8
CVE-2026-60294 CRITICAL
Oracle WebLogic Server 12.2.1.4.0/14.1.1.0.0/14.1.2.0.0/15.1.1.0.0 - Unauthenticated Remote Code Execution via SOAP
CVSS 9.8
CVE-2026-60292 CRITICAL
Oracle WebLogic Server 12.2.1.4.0, 14.1.1.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
Details
Vulnerabilities 2,845
Exploit Likelihood High