Known Vulnerabilities for User Management by Oracle
Listed below are 6 of the newest known vulnerabilities associated with "User Management" by "Oracle".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-88959 json | Anchor CMS through 0.12.7 fails to enforce role-based access control in admin user-management endpoints, allowing any authent... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-88770 json | A flaw was found in the Device Authorization Grant flow of Keycloak, an identity and access management solution. The issue oc... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-88061 json | career-ops is an open-source AI-assisted job search and application management tool. Prior to 0.8.0, the career-ops local web... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-88006 json | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.1, Open WebUI's O... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-86775 json | knowns (npm package) versions <= 0.29.1 contain a path traversal vulnerability in the Document API. The HTTP handler in inter... | Not Provided | 2026-09-09 | 2026-09-09 |
| CVE-2026-86769 json | Snipe-IT versions before 8.7.0 contain an improper ownership management vulnerability in the consumables checkout API endpoin... | Not Provided | 2026-09-09 | 2026-09-09 |
| CVE-2026-86762 json | Snipe-IT before 8.7.0 does not apply the CheckUserIsActivated middleware to the `api` middleware group in app/Http/Kernel.php... | Not Provided | 2026-09-09 | 2026-09-10 |
| CVE-2026-86754 json | Snipe-IT before 8.7.0 fails to properly gate Laravel Passport's OAuth client management routes, allowing any authenticated us... | Not Provided | 2026-09-09 | 2026-09-09 |
| CVE-2026-86747 json | Snipe-IT is an open source IT asset management system. In versions up to and including 8.6.3, the report acceptance endpoints... | Not Provided | 2026-09-09 | 2026-09-10 |
| CVE-2026-86745 json | Snipe-IT is an IT asset management application. In Snipe-IT master-branch builds after 8.6.3 (the code was never included in ... | Not Provided | 2026-09-09 | 2026-09-09 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Oracle | User Management | 12.2.7 | |||
| Application | Oracle | User Management | 12.2.6 | |||
| Application | Oracle | User Management | 12.2.5 | |||
| Application | Oracle | User Management | 12.2.4 | |||
| Application | Oracle | User Management | 12.2.3 | |||
| Application | Oracle | User Management | 12.2.10 | |||
| Application | Oracle | User Management | 12.1.3 |