Description
Vulnerability in the Siebel CRM Administration product of Oracle Siebel CRM (component: Data Archival). Supported versions that are affected are 25.12-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Administration. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Administration accessible data as well as unauthorized update, insert or delete access to some of Siebel CRM Administration accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
Published: 2026-08-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A low‑privileged attacker with network access via HTTP can exploit a flaw in the Data Archival component of Oracle Siebel CRM Administration. The vulnerability allows unauthorized read access to sensitive information and, in some scenarios, insert, update, or delete operations on that data, compromising confidentiality and integrity. The weakness is rooted in improper access control (CWE‑284).

Affected Systems

Oracle Siebel CRM Administration versions 25.12 through 26.6, specifically the Data Archival component, are affected. The issue is present in all builds of the Administration interface within that version range.

Risk and Exploitability

The CVSS v3.1 base score of 7.1 denotes a moderate‑to‑high risk impact. The EPSS score of less than 1% indicates a low probability of exploitation, but the flaw can be triggered over an accessible HTTP interface without elevated privileges. The vulnerability is not listed in CISA’s KEV catalog, suggesting no documented large‑scale exploitation yet, yet the ease of exploitation and high impact make it a priority to mitigate.

Generated by OpenCVE AI on August 21, 2026 at 09:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Siebel CRM Administration patch or upgrade to a version that contains the fix for the Data Archival component.
  • Restrict HTTP access to the Administration interface to trusted IP addresses or network segments, limiting exposure to only authorized hosts.
  • Enforce strict least‑privilege access controls for users who can view or modify data through the Administration interface, and audit any changes to critical data regularly.

Generated by OpenCVE AI on August 21, 2026 at 09:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Oracle siebel Crm
CPEs cpe:2.3:a:oracle:siebel_crm:*:*:*:*:*:*:*:*
Vendors & Products Oracle siebel Crm

Fri, 21 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Title Low‑privileged HTTP Remote Access for Sensitive Data via Siebel CRM Administration Data Archival

Fri, 21 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 19 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Title Low‑privileged HTTP Remote Access for Sensitive Data via Siebel CRM Administration Data Archival

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Administration product of Oracle Siebel CRM (component: Data Archival). Supported versions that are affected are 25.12-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Administration. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Administration accessible data as well as unauthorized update, insert or delete access to some of Siebel CRM Administration accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle siebel Crm Administration
CPEs cpe:2.3:a:oracle:siebel_crm_administration:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Administration
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Oracle Siebel Crm Siebel Crm Administration
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-21T03:56:16.753Z

Reserved: 2026-07-14T14:54:48.743Z

Link: CVE-2026-62587

cve-icon Vulnrichment

Updated: 2026-08-20T16:46:37.318Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:10.890

Modified: 2026-08-21T15:00:44.610

Link: CVE-2026-62587

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T10:00:04Z

Weaknesses