Description
Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions that are affected are 25.12-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Integration. While the vulnerability is in Siebel CRM Integration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Siebel CRM Integration. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-08-18
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Open Integration component of Oracle Siebel CRM allows a low‑privilege attacker possessing network access via HTTP to exploit the system. The vulnerability directly compromises confidentiality, integrity, and availability, potentially leading to a complete compromise of the Siebel CRM Integration service and affecting other connected applications.

Affected Systems

Oracle Corporation’s Siebel CRM Integration product, versions 25.12 through 26.6, is affected. Only the Siebel CRM Integration component is formally listed as vulnerable; other Oracle Siebel products may experience a scope change if compromised.

Risk and Exploitability

The CVSS score of 9.9 classifies this as critical, with the attack vector being network‑based (HTTP) and requiring low privilege. The EPSS score is below 1%, indicating a very low exploitation probability, but the high severity and ease of exploitation warrant immediate attention. The vulnerability can be leveraged by an attacker to gain full control over the integration module from a remote location without authentication, and the KEV catalog indicates it is not listed.

Generated by OpenCVE AI on August 21, 2026 at 11:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle security patch for Siebel CRM Integration as detailed in the August 2026 security alert.
  • If a patch is not yet available, restrict inbound HTTP traffic to the Siebel CRM Integration to trusted IP addresses only, effectively preventing unauthenticated access.
  • Segregate the integration service from the public network by placing it behind a VPN or internal firewall and verify that only authorized network segments can reach it.

Generated by OpenCVE AI on August 21, 2026 at 11:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Title Remote Attack Enables Full Takeover of Oracle Siebel CRM Integration

Fri, 21 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Title Remote Code Execution in Oracle Siebel CRM Integration via Unauthenticated HTTP Access
Weaknesses CWE-287

Thu, 20 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Oracle siebel Crm
CPEs cpe:2.3:a:oracle:siebel_crm:*:*:*:*:*:*:*:*
Vendors & Products Oracle siebel Crm

Thu, 20 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution in Oracle Siebel CRM Integration via Unauthenticated HTTP Access
Weaknesses CWE-284
CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions that are affected are 25.12-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Integration. While the vulnerability is in Siebel CRM Integration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Siebel CRM Integration. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle siebel Crm Integration
CPEs cpe:2.3:a:oracle:siebel_crm_integration:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Integration
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Siebel Crm Siebel Crm Integration
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T03:56:24.332Z

Reserved: 2026-07-14T14:54:48.743Z

Link: CVE-2026-62588

cve-icon Vulnrichment

Updated: 2026-08-19T17:32:42.515Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:11.003

Modified: 2026-08-20T15:10:34.050

Link: CVE-2026-62588

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T11:30:04Z

Weaknesses