Description
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.5. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Siebel CRM Cloud Applications accessible data as well as unauthorized read access to a subset of Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 4.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-07-21
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications and permits an unauthenticated attacker with access to the physical communication segment to modify, insert, or delete data, as well as read a subset of data the application exposes. The weakness reflects an improper access control flaw that compromises data confidentiality and integrity, allowing the attacker to tamper with stored information without authorization.

Affected Systems

Oracle Corporation’s Siebel CRM Cloud Applications, versions 22.3 through 26.5, are impacted. These versions contain the vulnerable Siebel Cloud Manager that fails to enforce proper authorization checks for data operations exposed over the local communication segment.

Risk and Exploitability

The CVSS v3.1 base score of 4.2 indicates moderate confidentiality and integrity impacts with local access as the attack vector, high attack complexity, no privileges or user interaction required, and unchanged scope. The EPSS score of less than 1% suggests a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the attacker to be physically present to reach the hardware’s communication segment; no network or remote access is necessary. Upon execution, the attacker can perform unauthorized data modifications or reads, potentially compromising sensitive customer information stored within the application.

Generated by OpenCVE AI on August 4, 2026 at 02:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Evaluate the extent of data at risk in your Siebel CRM deployments to understand potential impact.
  • Implement network segmentation or access controls that isolate the physical communication segment from untrusted devices or personnel.
  • Monitor audit logs for signs of unauthorized data modification or read activity, and investigate any abnormal events promptly.

Generated by OpenCVE AI on August 4, 2026 at 02:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Title Local Authorization Bypass in Oracle Siebel CRM Cloud Applications

Thu, 30 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Local Authorization Bypass in Oracle Siebel CRM Cloud Applications

Tue, 28 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Local Access Allows Unauthorized Data Modification in Siebel CRM Cloud Applications

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Local Access Allows Unauthorized Data Modification in Siebel CRM Cloud Applications
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.5. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Siebel CRM Cloud Applications accessible data as well as unauthorized read access to a subset of Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 4.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle siebel Crm Cloud Applications
CPEs cpe:2.3:a:oracle:siebel_crm_cloud_applications:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Cloud Applications
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Oracle Siebel Crm Siebel Crm Cloud Applications
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T19:05:40.311Z

Reserved: 2026-07-08T15:51:55.580Z

Link: CVE-2026-60709

cve-icon Vulnrichment

Updated: 2026-07-24T19:05:35.659Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:11.323

Modified: 2026-08-03T18:55:21.650

Link: CVE-2026-60709

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:00:02Z

Weaknesses