Description
Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this vulnerability can result in takeover of Siebel Apps - Marketing. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is found in the Marketing component of Oracle Siebel Apps - Marketing. A low‑privileged attacker who can reach the instance over HTTP can exploit the flaw to compromise the application. Successful exploitation can lead to a full takeover.

Affected Systems

Oracle Siebel Apps - Marketing, versions 17.0 through 26.6 are affected. The affected product is part of the Oracle Siebel CRM suite, specifically the Marketing application component.

Risk and Exploitability

The CVSS 3.1 base score of 7.5 indicates a high‑severity vulnerability with substantial impact on confidentiality, integrity, and availability. The EPSS score indicates a very low but non‑zero exploitation probability of less than 1%. The issue is not listed in CISA’s KEV catalog. The likely attack vector is over HTTP from a low‑privileged attacker. If successfully exploited, the attacker would gain full control over the application.

Generated by OpenCVE AI on August 26, 2026 at 23:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch or upgrade to a version that includes the fix for CVE-2026-60765 as outlined in the official advisory.
  • Restrict HTTP access to the Siebel Apps - Marketing application to trusted IP ranges or internal networks, thereby reducing the exposed attack surface for low‑privileged users.
  • Enforce strict least‑privilege configuration for user accounts connected to the application and monitor logs for suspicious activity.

Generated by OpenCVE AI on August 26, 2026 at 23:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Oracle Siebel Apps - Marketing: Low-Privileged HTTP-Based Application Takeover Vulnerability

Wed, 26 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-346

Fri, 21 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title Oracle Siebel Apps - Marketing: Low-Privileged HTTP-Based Application Takeover Vulnerability

Thu, 20 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this vulnerability can result in takeover of Siebel Apps - Marketing. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle siebel Apps - Marketing
CPEs cpe:2.3:a:oracle:siebel_apps_-_marketing:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Apps - Marketing
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Siebel Apps - Marketing
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T19:29:44.732Z

Reserved: 2026-07-08T15:51:55.588Z

Link: CVE-2026-60765

cve-icon Vulnrichment

Updated: 2026-08-20T19:26:15.473Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:42.523

Modified: 2026-08-26T15:52:11.183

Link: CVE-2026-60765

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T00:00:11Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function

  • CWE-346

    Origin Validation Error