Description
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Compromise and takeover of Siebel CRM Cloud Applications
Action: Patch
AI Analysis

Impact

The vulnerability exists in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications and allows an attacker with low privilege who can reach the application via HTTP to accomplish a full takeover. The flaw can be exploited directly through the web interface, permitting an attacker to execute actions that compromise confidentiality, integrity, and availability of the application and its underlying data. Successful exploitation results in loss of customer data, the ability to alter business processes, and potential service disruption.

Affected Systems

Oracle Corporation’s Siebel CRM Cloud Applications – versions 22.3 to 26.6 – are impacted. All Cloud Manager deployments within that version range are vulnerable, as indicated by Oracle’s August 2026 security alert. This cloud‑based CRM platform is accessed via HTTP or HTTPS, and the issue pertains specifically to the Siebel Cloud Manager component.

Risk and Exploitability

The CVSS 3.1 base score of 8.8 indicates high severity, with full confidentiality, integrity, and availability impacts. The EPSS score is < 1%, indicating a very low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is network‑based (HTTP), with low attack complexity, low privilege required, and no user interaction needed; an automated script could therefore be effective. Organizations running the affected versions should treat this as a critical exposure until a vendor patch is applied.

Generated by OpenCVE AI on August 21, 2026 at 11:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and apply the latest Oracle patch for Siebel CRM Cloud Applications 22.3‑26.6 as outlined in the August 2026 security alert.
  • Restrict HTTP access to the Siebel Cloud Manager endpoints to authorized users only, such as by limiting connections to trusted IP ranges or VPN tunnels.
  • Verify that the deployment’s authentication and authorization configuration follows best practices and disable any legacy or default administrative accounts that may be exploitable.

Generated by OpenCVE AI on August 21, 2026 at 11:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Oracle siebel Crm
CPEs cpe:2.3:a:oracle:siebel_crm:*:*:*:*:*:*:*:*
Vendors & Products Oracle siebel Crm

Fri, 21 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Title Siebel CRM Cloud Manager HTTP Exploit Enabling Application Takeover

Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Siebel CRM Cloud Manager HTTP Exploit Enabling Application Takeover
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle siebel Crm Cloud Applications
CPEs cpe:2.3:a:oracle:siebel_crm_cloud_applications:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Cloud Applications
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Siebel Crm Siebel Crm Cloud Applications
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-21T03:56:06.698Z

Reserved: 2026-07-08T15:52:20.748Z

Link: CVE-2026-61341

cve-icon Vulnrichment

Updated: 2026-08-20T16:38:29.145Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:00.910

Modified: 2026-09-01T19:55:54.027

Link: CVE-2026-61341

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:00:11Z

Weaknesses