Description
Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel Apps - Marketing accessible data as well as unauthorized access to critical data or complete access to all Siebel Apps - Marketing accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-08-18
Score: 7.4 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated attacker with network access to the Siebel Apps – Marketing HTTP interface can create, delete, or modify critical data or gain full access to all available data. This results in a loss of confidentiality and integrity of the application’s data, as the attacker can alter or wipe records. The vulnerability does not affect availability, but its exploitation grants extensive control over stored information.

Affected Systems

Oracle Siebel CRM’s Marketing component, versions 17.0 through 26.6, are vulnerable. All instances running these versions are exposed to the described attack vector via HTTP traffic.

Risk and Exploitability

The CVSS 3.1 score of 7.4 indicates a high severity risk, with high impact on confidentiality and integrity but no impact on availability. Although the EPSS score is not available, the public advisory and high CVSS suggest a moderate to high likelihood of exploitation. The vulnerability is reachable over the network without authentication or user interaction, and the attacker must have network visibility to the HTTP interface. As it is not listed in CISA’s KEV catalog, there is no current evidence of widespread exploitation, but the potential damage warrants prompt action.

Generated by OpenCVE AI on August 18, 2026 at 23:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch or upgrade Siebel Apps – Marketing to a version newer than 26.6, which includes the fix for this access‑control vulnerability.
  • Restrict HTTP access to the Siebel Marketing service to trusted IP addresses or internal networks using firewall or ACL rules to reduce the attack surface for unauthenticated users.
  • Configure logging and monitor for anomalous SQL or service calls that indicate unauthorized creation, deletion, or modification of records, and investigate any suspicious activity promptly.

Generated by OpenCVE AI on August 18, 2026 at 23:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel Apps - Marketing accessible data as well as unauthorized access to critical data or complete access to all Siebel Apps - Marketing accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle siebel Apps - Marketing
CPEs cpe:2.3:a:oracle:siebel_apps_-_marketing:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Apps - Marketing
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Siebel Apps - Marketing
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:59:11.248Z

Reserved: 2026-07-08T15:51:55.592Z

Link: CVE-2026-60803

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:43.930

Modified: 2026-08-18T21:16:43.930

Link: CVE-2026-60803

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T00:00:04Z

Weaknesses