Description
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Siebel CRM Cloud Applications accessible data as well as unauthorized read access to a subset of Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-07-21
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications. It permits a low‑privileged local attacker that has logged onto the underlying infrastructure to modify, delete, or insert data, and to read a subset of the application’s data. While the CVSS score of 4.4 reflects limited confidentiality and integrity impact, the ability to alter organisational data can have significant operational repercussions.

Affected Systems

Oracle Siebel CRM Cloud Applications versions 22.3 through 26.5 are affected. The issue specifically involves the Siebel Cloud Manager component, a core part of the stack provided by Oracle Corporation.

Risk and Exploitability

The CVSS base score of 4.4 and an EPSS score below 1% indicate that the vulnerability is not highly generalised and the likelihood of exploitation is low. It is not listed in the CISA KEV catalog. The exploit requires local system access; an attacker would need to be able to log onto the host where the application runs. Because no public exploit is known, the risk remains primarily confined to internal users with insufficient privileges. Nonetheless, the potential for unauthorized data alteration warrants prompt action.

Generated by OpenCVE AI on August 4, 2026 at 02:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any Oracle‑issued patch or upgrade to a version later than 26.5 that resolves the local‑access data modification issue.
  • Enforce strict role‑based access controls on the infrastructure hosting the application, limiting logon rights to trusted administrators.
  • Regularly audit the Siebel CRM Cloud Applications logs for unauthorized data modifications or suspicious activity.

Generated by OpenCVE AI on August 4, 2026 at 02:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title Local Access Data Modification and Read Privileges in Siebel CRM Cloud Applications

Thu, 30 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Local attacker can modify or delete data in Siebel CRM Cloud Applications

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Local attacker can modify or delete data in Siebel CRM Cloud Applications
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Siebel CRM Cloud Applications accessible data as well as unauthorized read access to a subset of Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle siebel Crm Cloud Applications
CPEs cpe:2.3:a:oracle:siebel_crm_cloud_applications:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Cloud Applications
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Oracle Siebel Crm Siebel Crm Cloud Applications
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T18:15:58.541Z

Reserved: 2026-07-08T15:51:55.581Z

Link: CVE-2026-60713

cve-icon Vulnrichment

Updated: 2026-07-24T18:15:54.620Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:11.790

Modified: 2026-08-03T20:36:09.070

Link: CVE-2026-60713

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:00:02Z

Weaknesses