Description
Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM Integration. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).
Published: 2026-08-18
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the REST component of Oracle Siebel CRM Integration and permits an unauthenticated attacker to access any data exposed by the integration. The flaw can also trigger a partial denial of service. It is an improper access control weakness that violates confidentiality and availability goals.

Affected Systems

Oracle Siebel CRM Integration, versions 17.0 through 26.6 the product is affected.

Risk and Exploitability

The CVSS 3.1 base score of 8.2 indicates a high severity. The EPSS score is < 1% and the issue is not listed in CISA’s KEV catalog. The likely attack vector is an external network attacker sending HTTP requests to the exposed REST interface. In the absence of authentication, the attacker can retrieve critical data and, by abusing the interface, may cause a partial denial of service.

Generated by OpenCVE AI on August 21, 2026 at 15:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for Siebel CRM Integration covering versions 17.0–26.6
  • Configure network controls to restrict HTTP access to trusted hosts and require authentication before reaching the REST API
  • If the REST service is not required, disable or remove the integration endpoint to eliminate the attack surface

Generated by OpenCVE AI on August 21, 2026 at 15:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Oracle siebel Crm
CPEs cpe:2.3:a:oracle:siebel_crm:*:*:*:*:*:*:*:*
Vendors & Products Oracle siebel Crm

Fri, 21 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Title Unauthorized data exposure and partial denial of service vulnerability in Oracle Siebel CRM Integration

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM Integration. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).
First Time appeared Oracle
Oracle siebel Crm Integration
CPEs cpe:2.3:a:oracle:siebel_crm_integration:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Integration
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L'}


Subscriptions

Oracle Siebel Crm Siebel Crm Integration
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T12:55:19.326Z

Reserved: 2026-07-08T15:51:55.591Z

Link: CVE-2026-60796

cve-icon Vulnrichment

Updated: 2026-08-19T12:13:36.566Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:43.583

Modified: 2026-08-26T14:09:21.987

Link: CVE-2026-60796

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T15:45:18Z

Weaknesses