Description
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Application Interface). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Siebel CRM Deployment executes to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Deployment accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-08-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Application Interface of the Siebel CRM Deployment product. An unauthenticated attacker who can reach the physical communication segment that hosts the application can exploit the flaw to create, delete or modify data. Successful exploitation results in unauthorized access to or complete compromise of all data stored or processed by Siebel CRM Deployment, threatening both confidentiality and integrity.

Affected Systems

Oracle Siebel CRM Deployment is affected for all supported versions from 17.0 through 26.6. The flaw is present in the Application Interface component of the system.

Risk and Exploitability

The flaw is rated with a CVSS 3.1 base score of 8.1, indicating high severity. The exploit vector is local (AV:A) with low attack complexity (AC:L). The EPSS score is 0.00225 (<1%), indicating a very low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Given that the attack requires physical or network segment access to the deployment, the flaw can be considered easily exploitable under those conditions, but the overall likelihood reflected by EPSS remains low.

Generated by OpenCVE AI on August 21, 2026 at 16:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Oracle patch for Siebel CRM Deployment that addresses this local access control flaw for versions 17.0 through 26.6.
  • Restrict physical and network access to the communication segment that hosts Siebel CRM Deployment; segment the network or apply firewall rules to block unauthenticated connections.
  • Enable detailed logging on Siebel CRM Deployment and monitor for unauthorized data creation, deletion, or modification; set up alerts to detect abnormal activity.
  • If a patch is not immediately available, apply a temporary network-based workaround by limiting access to the Siebel servers to a trusted list of IPs or requiring VPN authentication before allowing communication.

Generated by OpenCVE AI on August 21, 2026 at 16:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Oracle siebel Crm
CPEs cpe:2.3:a:oracle:siebel_crm:*:*:*:*:*:*:*:*
Vendors & Products Oracle siebel Crm

Fri, 21 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Siebel CRM Deployment Local Access Control Vulnerability

Wed, 19 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Application Interface). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Siebel CRM Deployment executes to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Deployment accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle siebel Crm Deployment
CPEs cpe:2.3:a:oracle:siebel_crm_deployment:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Deployment
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Siebel Crm Siebel Crm Deployment
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T03:56:46.610Z

Reserved: 2026-07-08T15:51:55.591Z

Link: CVE-2026-60791

cve-icon Vulnrichment

Updated: 2026-08-19T19:11:00.706Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:43.350

Modified: 2026-08-26T15:16:33.000

Link: CVE-2026-60791

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T16:15:03Z

Weaknesses