Description
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications. While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability in Oracle Siebel CRM Cloud Applications, specifically the Siebel Cloud Manager component, allows a user with local credentials who hosts the application to compromise the application and read or write all data handled by the service. The flaw is classified as a high confidentiality compromise, with no impact on integrity or availability, and is rated with a CVSS 3.1 base score of 6.5.

Affected Systems

Affected systems are Siebel CRM Cloud Applications, including the Siebel Cloud Manager, across all supported releases from version 22.3 through 26.5. Versions 26.6 and later contain the fix and are recommended for secure operation.

Risk and Exploitability

The vulnerability's CVSS score of 6.5 suggests moderate severity, while an EPSS score of less than 1 % indicates that exploitation is currently low probability. However, the attack has a local prerequisite; an attacker must already have logged into the application’s underlying infrastructure, a condition that is often within reach for low‑privileged staff or compromised accounts. Once the local compromise is achieved, the change in scope allows the attacker to potentially affect additional applications running in the same environment. The vulnerability is not listed in the CISA KEV catalog, but its potential to broaden access beyond the target application warrants careful monitoring and quick remediation.

Generated by OpenCVE AI on August 2, 2026 at 21:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Siebel CRM Cloud Applications July 2026 security patch that fixes the vulnerability in the Siebel Cloud Manager component.
  • Upgrade the application to version 26.6 or later, which incorporates the fix and any subsequent improvements.
  • Restrict local console or remote access rights on the infrastructure that hosts the Siebel CRM Cloud, ensuring that only authorized administrators and privileged accounts can log on, thereby reducing the attack surface for local attackers.

Generated by OpenCVE AI on August 2, 2026 at 21:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Siebel Cloud Manager Enables Unauthorized Data Access

Sat, 01 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Logon Allows Unauthorized Data Access in Oracle Siebel CRM Cloud
Weaknesses CWE-284

Thu, 30 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Logon Allows Unauthorized Data Access in Oracle Siebel CRM Cloud
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications. While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle siebel Crm Cloud Applications
CPEs cpe:2.3:a:oracle:siebel_crm_cloud_applications:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Cloud Applications
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Siebel Crm Siebel Crm Cloud Applications
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-30T16:48:14.516Z

Reserved: 2026-07-08T15:51:55.581Z

Link: CVE-2026-60712

cve-icon Vulnrichment

Updated: 2026-07-24T18:17:15.479Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:11.670

Modified: 2026-08-03T20:31:33.090

Link: CVE-2026-60712

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T21:15:02Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function

  • CWE-862

    Missing Authorization