Description
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Siebel Cloud Manager component of Oracle’s Siebel CRM Cloud Applications allows an unauthenticated attacker who can reach the system over the network to gain unauthorized read access to the application data. The vulnerability, identified as CWE‑306, is caused by inadequate authentication controls that permit remote exploitation via standard HTTP traffic. Because the issue can be triggered without credentials, the confidentiality of data stored in the CRM is directly threatened.

Affected Systems

Oracle Corporation’s Siebel CRM Cloud Applications, specifically the Siebel Cloud Manager component, is affected for supported releases 22.3 through 26.5. Systems deploying these versions should confirm the installation of the component and the exact patch level.

Risk and Exploitability

The attack vector is network‑based using normal HTTP requests; authentication is not required. The EPSS score is below 1 %, indicating that broad exploitation is presently unlikely, and the vulnerability is not listed in CISA’s KEV catalog. Still, the combination of remote access, lack of authentication, and high confidentiality impact gives the CVSS score of 7.5 a significant risk level to data confidentiality if the flaw were to be leveraged.

Generated by OpenCVE AI on August 2, 2026 at 21:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CPU July 2026 security patch for Siebel Cloud Manager to all affected systems.
  • Block external HTTP access to the Siebel CRM Cloud Applications from untrusted networks until the patch can be applied.
  • Continuously monitor network traffic and application logs for unauthorized access attempts or suspicious activity.

Generated by OpenCVE AI on August 2, 2026 at 21:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthorized HTTP Access Enables Data Exfiltration in Oracle Siebel CRM Cloud Applications

Mon, 27 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access Vulnerability in Oracle Siebel CRM Cloud Manager
Weaknesses CWE-284
CWE-287

Fri, 24 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access Vulnerability in Oracle Siebel CRM Cloud Manager
Weaknesses CWE-284
CWE-287

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle siebel Crm Cloud Applications
CPEs cpe:2.3:a:oracle:siebel_crm_cloud_applications:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Cloud Applications
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Siebel Crm Siebel Crm Cloud Applications
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-25T03:55:48.486Z

Reserved: 2026-07-08T15:51:55.578Z

Link: CVE-2026-60689

cve-icon Vulnrichment

Updated: 2026-07-24T18:30:46.097Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:09.703

Modified: 2026-08-03T20:32:48.990

Link: CVE-2026-60689

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T21:30:04Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function