Description
Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel Apps - Marketing accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel Apps - Marketing. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).
Published: 2026-08-18
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated attacker with network connectivity to the Siebel Apps - Marketing HTTP interface can compromise the application due to a CWE‑284 weakness. The flaw grants unauthorized access to all data stored by the marketing component and enables an attacker to cause a hang or recurring crash, resulting in a denial of service. The CVSS v3.1 score of 9.1 reflects severe confidentiality impact and total availability impact.

Affected Systems

Oracle Siebel CRM’s Siebel Apps - Marketing product is affected. Versions from 17.0 up to and including 26.6 are vulnerable. Any installation within this range that exposes the HTTP interface to an external network can be exploited.

Risk and Exploitability

The high CVSS score indicates a critical severity. The EPSS score of < 1% indicates a low probability of exploitation, and the vulnerability is listed as not in CISA KEV, indicating no publicly confirmed exploitation yet. The attack vector is purely network based and requires no authentication; an unauthenticated HTTP connection to the vulnerable endpoint is sufficient to gain full data access and trigger service crashes.

Generated by OpenCVE AI on August 21, 2026 at 15:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle-published patch for Siebel Apps - Marketing versions 17.0 through 26.6 as outlined in the security alert
  • Restrict HTTP access to the Siebel Applications by using firewalls or IP whitelisting to limit the interface to trusted users or networks
  • Enable logging and monitor for repeated authentication failures or unexpected service restarts as a defensive indicator

Generated by OpenCVE AI on August 21, 2026 at 15:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access and Denial of Service in Oracle Siebel Apps - Marketing

Thu, 20 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel Apps - Marketing accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel Apps - Marketing. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).
First Time appeared Oracle
Oracle siebel Apps - Marketing
CPEs cpe:2.3:a:oracle:siebel_apps_-_marketing:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Apps - Marketing
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}


Subscriptions

Oracle Siebel Apps - Marketing
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T17:07:32.485Z

Reserved: 2026-07-08T15:51:55.587Z

Link: CVE-2026-60754

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:42.043

Modified: 2026-08-26T16:02:42.583

Link: CVE-2026-60754

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T16:00:15Z

Weaknesses