Description
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.5. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data as well as unauthorized update, insert or delete access to some of Siebel CRM Cloud Applications accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L).
Published: 2026-07-21
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Siebel CRM Cloud Applications originates from the Siebel Cloud Manager component and permits an unauthenticated attacker with network access to perform unauthorized operations without authentication. The flaw enables the attacker to read critical data, modify or delete records, and even make the application partially unavailable. These capabilities correspond to a high confidentiality impact, low integrity impact, and a low availability impact, as captured by a CVSS score of 7.0.

Affected Systems

Affected systems are Oracle Siebel CRM Cloud Applications versions 22.3 through 26.5. All organizations running any of these versions are exposed unless a compatible patch has been installed.

Risk and Exploitability

The risk is moderate to high given the CVSS base score but the EPSS score is below 1% and the vulnerability is not listed in CISA’s KEV catalog, which indicates low current exploit activity. Based on the description, it is inferred that the likely attack vector is network access via HTTP to the Siebel Cloud Manager. Attackers would need only access to the HTTP interface of the Siebel Cloud Manager, making the attack vector local network or internet if the interface is exposed. Based on the description, it is inferred that the vulnerability represents an authentication bypass, as no authentication or privilege is required, leading to privilege escalation within the application.

Generated by OpenCVE AI on August 5, 2026 at 01:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle security patch for Siebel CRM Cloud Applications that addresses CVE-2026-60705.
  • Restrict HTTP access to the Siebel Cloud Manager endpoints using firewalls or ACLs until the patch is applied.
  • Monitor HTTP traffic and application logs for unexpected read or write requests against Siebel data to detect exploitation attempts.

Generated by OpenCVE AI on August 5, 2026 at 01:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access in Siebel CRM Cloud Manager Enables Data Breach and Partial DoS

Thu, 30 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access in Siebel CRM Cloud Manager Enables Data Breach and Partial DoS

Mon, 27 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enabling Unauthorized Data Manipulation in Siebel CRM Cloud Applications

Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enabling Unauthorized Data Manipulation in Siebel CRM Cloud Applications
Weaknesses CWE-284
CWE-306

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.5. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data as well as unauthorized update, insert or delete access to some of Siebel CRM Cloud Applications accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L).
First Time appeared Oracle
Oracle siebel Crm Cloud Applications
CPEs cpe:2.3:a:oracle:siebel_crm_cloud_applications:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Cloud Applications
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L'}


Subscriptions

Oracle Siebel Crm Siebel Crm Cloud Applications
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T19:15:27.475Z

Reserved: 2026-07-08T15:51:55.580Z

Link: CVE-2026-60705

cve-icon Vulnrichment

Updated: 2026-07-24T19:15:22.515Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:10.940

Modified: 2026-08-03T20:37:23.877

Link: CVE-2026-60705

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T02:00:12Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control

  • CWE-306

    Missing Authentication for Critical Function