Description
Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Integration accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-08-18
Score: 7.4 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated external attacker who can reach the Siebel CRM Integration REST API over HTTP can create, delete, or modify critical data without any authentication. The flaw allows the attacker to bypass normal access controls, resulting in confidentiality and integrity compromise of all data accessible through the integration. This weakness is consistent with an Improper Access Control flaw (CWE-284).

Affected Systems

Oracle Siebel CRM Integration 17.0 through 26.6 are affected. Any installation of these versions that exposes the REST interface to a network is susceptible to exploitation.

Risk and Exploitability

The CVSS v3.1 score of 7.4 indicates high severity with significant confidentiality and integrity impact, but without network exploitation prerequisites. Exploitation requires only network access to the HTTP endpoint, making it possible from any system able to reach the API, though the vulnerability is described as difficult to exploit. The EPSS score is unavailable, and the vulnerability is not listed in CISA KEV. Attackers would send crafted REST requests to a vulnerable instance to gain unauthorized access and modify or delete data.

Generated by OpenCVE AI on August 18, 2026 at 23:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch or update to a non‑affected version when available.
  • Limit access to the Siebel CRM Integration REST API to trusted networks or VPNs and block all other inbound traffic.
  • Enable and monitor audit logging for all REST actions to detect any unauthorized creation, deletion, or modification attempts.

Generated by OpenCVE AI on August 18, 2026 at 23:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access to Siebel CRM Integration via REST API Allowing Unauthorized Data Modification
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Integration accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle siebel Crm Integration
CPEs cpe:2.3:a:oracle:siebel_crm_integration:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Integration
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Siebel Crm Integration
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:59:11.871Z

Reserved: 2026-07-08T15:51:55.593Z

Link: CVE-2026-60820

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:44.163

Modified: 2026-08-18T21:16:44.163

Link: CVE-2026-60820

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T00:00:04Z

Weaknesses