Description
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability resides in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications. It is a missing authentication flaw (CWE‑306) that allows an unauthenticated attacker with network connectivity to HTTP access to retrieve sensitive data. No authentication is required, and the attack can be performed from an external network, directly compromising confidentiality without affecting integrity or availability.

Affected Systems

Oracle Siebel CRM, specifically the Siebel CRM Cloud Applications product for versions 22.3 through 26.5.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity condition for confidentiality. The low EPSS score of less than 1 % signifies a small likelihood of exploitation at present, though the vulnerability remains publicly known and not yet recorded in CISA's KEV catalog. Attackers would likely target exposed HTTP endpoints of the Siebel Cloud Manager, which are currently reachable without authentication, to obtain critical data. The lack of authentication and only the need for network access reduce the attacker’s effort and prerequisites.

Generated by OpenCVE AI on August 2, 2026 at 21:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade or patch Oracle Siebel CRM Cloud Applications following the instructions in the CPU July 2026 advisory.
  • Configure the firewall or network segmentation to restrict HTTP access to the Siebel Cloud Manager interface to trusted IP ranges only.
  • Disable or shield any publicly accessible endpoints that allow administrative or data‑retrieval operations until the patch is applied.

Generated by OpenCVE AI on August 2, 2026 at 21:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Missing Authentication in Oracle Siebel CRM Cloud Manager Exposes Sensitive Data

Wed, 29 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Authorization Bypass Leading to Confidential Data Exposure in Siebel CRM Cloud Applications
Weaknesses CWE-284

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Authorization Bypass Leading to Confidential Data Exposure in Siebel CRM Cloud Applications
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle siebel Crm Cloud Applications
CPEs cpe:2.3:a:oracle:siebel_crm_cloud_applications:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Cloud Applications
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Siebel Crm Siebel Crm Cloud Applications
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-29T19:26:43.143Z

Reserved: 2026-07-08T15:51:55.580Z

Link: CVE-2026-60704

cve-icon Vulnrichment

Updated: 2026-07-24T18:32:50.853Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:10.830

Modified: 2026-08-03T20:32:02.737

Link: CVE-2026-60704

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T21:15:02Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function