Description
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Siebel Cloud Manager component of Oracle’s Siebel CRM Cloud Applications allows a remote attacker with low privileges but network access via HTTP to manipulate the system and potentially gain full control. The vulnerability compromises confidentiality, integrity, and availability, and the CVSS score of 9.9 reflects a critical exploitation scenario.

Affected Systems

Oracle Siebel CRM Cloud Applications versions 22.3 through 26.5 are affected. The attack may also impact additional products because the vulnerability changes the scope of privileges granted to the attacker.

Risk and Exploitability

The CVSS score of 9.9 indicates maximum severity, but the EPSS score is listed as < 1%, suggesting that, as of this assessment, the probability of exploitation is extremely low and the vulnerability is not currently included in the CISA KEV catalog. The likely attack vector is over the network using HTTP and requires only low‑privileged authentication to succeed.

Generated by OpenCVE AI on August 2, 2026 at 21:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor‑provided patch or upgrade to a non‑affected version (if available).
  • Restrict HTTP access to the Siebel Cloud Manager to ranges or use a VPN.
  • Monitor system logs and network traffic for anomalous activity.

Generated by OpenCVE AI on August 2, 2026 at 21:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title Remote takeover vulnerability in Oracle Siebel CRM Cloud Applications

Thu, 30 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Siebel CRM Cloud Applications Low‑Privilege Remote Attack Enables Full System Takeover

Sun, 26 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Siebel CRM Cloud Applications Low‑Privilege Remote Attack Enables Full System Takeover

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle siebel Crm Cloud Applications
CPEs cpe:2.3:a:oracle:siebel_crm_cloud_applications:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Cloud Applications
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Siebel Crm Siebel Crm Cloud Applications
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-25T03:55:46.526Z

Reserved: 2026-07-08T15:51:55.581Z

Link: CVE-2026-60711

cve-icon Vulnrichment

Updated: 2026-07-24T18:27:25.325Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:11.553

Modified: 2026-08-03T20:36:20.970

Link: CVE-2026-60711

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T21:15:02Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function