Description
Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Siebel CRM Integration. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Integration accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-08-18
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability in the REST component of Oracle Siebel CRM Integration allows an unauthenticated attacker with network access over HTTPS to create, delete, or modify critical data. This flaw can result in significant integrity violations affecting all data exposed by the integration.

Affected Systems

Affected products are Oracle Siebel CRM Integration. Supported versions 17.0 through 26.6 are vulnerable. All environments running these versions are at risk unless updated.

Risk and Exploitability

The CVSS v3.1 score of 7.4 indicates a high impact on confidentiality and integrity but no impact on availability. Exploitation requires only network access over HTTPS and is described as difficult; the EPSS score is 0.00301 (<1%), and the vulnerability is not listed in the CISA KEV catalog. Despite the lack of availability impact, the absence of authentication makes this a serious threat for systems exposed to external connections.

Generated by OpenCVE AI on August 21, 2026 at 17:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Siebel CRM Integration to a patched version that resolves the REST API issue.
  • Apply any Oracle‑supplied security patches immediately.
  • Restrict inbound HTTPS access to the REST endpoints to trusted networks or VPNs.
  • Enable logging and monitoring of the REST API for anomalous activity.

Generated by OpenCVE AI on August 21, 2026 at 17:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Oracle siebel Crm
CPEs cpe:2.3:a:oracle:siebel_crm:*:*:*:*:*:*:*:*
Vendors & Products Oracle siebel Crm

Fri, 21 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated REST API Data Modification in Oracle Siebel CRM Integration

Fri, 21 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTPS REST API vulnerability leads to data creation, deletion, and modification in Oracle Siebel CRM Integration
Weaknesses CWE-200

Wed, 19 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTPS REST API vulnerability leads to data creation, deletion, and modification in Oracle Siebel CRM Integration
Weaknesses CWE-200
CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Siebel CRM Integration. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Integration accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle siebel Crm Integration
CPEs cpe:2.3:a:oracle:siebel_crm_integration:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Integration
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Siebel Crm Siebel Crm Integration
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T03:56:08.842Z

Reserved: 2026-07-08T15:51:55.591Z

Link: CVE-2026-60797

cve-icon Vulnrichment

Updated: 2026-08-19T15:08:13.042Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:43.697

Modified: 2026-08-26T14:02:49.090

Link: CVE-2026-60797

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T18:00:16Z

Weaknesses