Description
Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Siebel CRM Integration. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Integration accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-08-18
Score: 7.4 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability in the REST component of Oracle Siebel CRM Integration allows an unauthenticated attacker with network access over HTTPS to create, delete, or modify critical data. Because authentication is not required, the flaw can lead to unauthorized disclosure of information and significant integrity violations, potentially affecting all data exposed by the integration.

Affected Systems

Affected products are Oracle Siebel CRM Integration. Supported versions 17.0 through 26.6 are vulnerable. All environments running these versions are at risk unless updated.

Risk and Exploitability

The CVSS v3.1 score of 7.4 indicates a high impact on confidentiality and integrity but no impact on availability. Exploitation requires only network access over HTTPS and is described as difficult; the EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog. Despite the lack of availability impact, the absence of authentication makes this a serious threat for systems exposed to external connections.

Generated by OpenCVE AI on August 18, 2026 at 23:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Siebel CRM Integration to a patched version that resolves the REST API issue.
  • Apply any Oracle‑supplied security patches immediately.
  • Restrict inbound HTTPS access to the REST endpoints to trusted networks or VPNs.
  • Enable logging and monitoring of the REST API for anomalous activity.

Generated by OpenCVE AI on August 18, 2026 at 23:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTPS REST API vulnerability leads to data creation, deletion, and modification in Oracle Siebel CRM Integration
Weaknesses CWE-200
CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Siebel CRM Integration. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Integration accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle siebel Crm Integration
CPEs cpe:2.3:a:oracle:siebel_crm_integration:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Integration
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Siebel Crm Integration
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:59:10.617Z

Reserved: 2026-07-08T15:51:55.591Z

Link: CVE-2026-60797

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:43.697

Modified: 2026-08-18T21:16:43.697

Link: CVE-2026-60797

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T00:00:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control