Description
Vulnerability in the Siebel CRM Administration product of Oracle Siebel CRM (component: Data Archival). Supported versions that are affected are 25.12-26.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Administration. While the vulnerability is in Siebel CRM Administration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Administration accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-08-18
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Data Archival component of Oracle Siebel CRM Administration. It permits an unauthenticated attacker who can reach the system over HTTP to compromise the administration interface. The weakness allows the attacker to bypass authentication and obtain or modify sensitive data stored in Siebel CRM Administration, potentially affecting the confidentiality of business information. No integrity or availability impact is reported, but the adversary can gain full access to all data exposed through the affected component.

Affected Systems

Oracle’s Siebel CRM Administration product is impacted. Affected versions span from 25.12 through 26.6 of the product. This includes all installations of the Data Archival component within those version ranges.

Risk and Exploitability

The CVSS 3.1 score of 8.6 indicates a high severity with a network attack vector, low attack complexity, and no user interaction required. The lack of a known exploitation probability (EPSS not available) suggests a recognized but unquantified risk. The vulnerability is not listed in CISA’s KEV catalog, yet because the weakness allows unauthenticated access and scope change, it can still expose broader systems and data. The likely attack path is an HTTP request to the vulnerable endpoint, exploiting the missing authentication controls, which can be performed remotely without any special user credentials.

Generated by OpenCVE AI on August 21, 2026 at 09:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle security patch detailed in the August 2026 security alert which addresses the Data Archival component.
  • If the patch cannot be applied immediately, restrict HTTP traffic to the Siebel CRM Administration server to known, trusted IP addresses via firewall rules or VPN.
  • Disable the Data Archival endpoint or service until the patch is deployed to eliminate the attack surface.

Generated by OpenCVE AI on August 21, 2026 at 09:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Oracle siebel Crm
CPEs cpe:2.3:a:oracle:siebel_crm:*:*:*:*:*:*:*:*
Vendors & Products Oracle siebel Crm

Fri, 21 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Access Exploit in Oracle Siebel CRM Administration

Fri, 21 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Access Exploit in Oracle Siebel CRM Administration
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Administration product of Oracle Siebel CRM (component: Data Archival). Supported versions that are affected are 25.12-26.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Administration. While the vulnerability is in Siebel CRM Administration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Administration accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle siebel Crm Administration
CPEs cpe:2.3:a:oracle:siebel_crm_administration:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Administration
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Siebel Crm Siebel Crm Administration
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-21T03:56:15.652Z

Reserved: 2026-07-14T14:54:48.743Z

Link: CVE-2026-62586

cve-icon Vulnrichment

Updated: 2026-08-20T16:46:36.384Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:10.773

Modified: 2026-08-21T14:59:01.883

Link: CVE-2026-62586

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:17:11Z

Weaknesses