Description
Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions that are affected are 25.12-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Integration. While the vulnerability is in Siebel CRM Integration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-08-18
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an improper access control issue in Oracle Siebel CRM Integration’s Open Integration component. An attacker who is not privileged but can reach the service over HTTP can bypass normal authentication checks and read any data exposed through the integration, potentially compromising sensitive business information. The vulnerability mainly affects confidentiality, but because the Flaw’s scope can expand to other products, a successful compromise could provide a foothold for further attacks.

Affected Systems

Oracle Siebel CRM Integration (Open Integration) versions 25.12 through 26.6 are affected. Systems that expose these services to external networks or accessible over public or untrusted internal networks are vulnerable.

Risk and Exploitability

The CVSS v3.1 score of 7.7 reflects a high impact with confidentiality as the primary concern. The attack vector is clearly network‑based, the attack complexity is low, and the required privileges are low, with no user interaction. The EPSS score is <1%, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the ease of exploitation and potential for broader product impact warrant immediate remediation.

Generated by OpenCVE AI on August 21, 2026 at 09:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle‑provided security patch or upgrade to a version that no longer includes the affected range.
  • Restrict access to the Siebel CRM Integration HTTP endpoints by allowing only trusted internal IP addresses or by placing the service behind a dedicated firewall or reverse proxy.
  • Configure comprehensive audit logging on the integration endpoints and actively monitor for anomalous or unauthorized access attempts.

Generated by OpenCVE AI on August 21, 2026 at 09:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle Siebel CRM Integration Enables Unauthorized Data Access

Thu, 20 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Oracle siebel Crm
CPEs cpe:2.3:a:oracle:siebel_crm:*:*:*:*:*:*:*:*
Vendors & Products Oracle siebel Crm

Thu, 20 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 19 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control Exposes Oracle Siebel CRM Integration Data
Weaknesses CWE-200
CWE-284

Wed, 19 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control Exposes Oracle Siebel CRM Integration Data
Weaknesses CWE-200
CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions that are affected are 25.12-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Integration. While the vulnerability is in Siebel CRM Integration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle siebel Crm Integration
CPEs cpe:2.3:a:oracle:siebel_crm_integration:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Integration
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Siebel Crm Siebel Crm Integration
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T03:56:25.512Z

Reserved: 2026-07-14T14:54:48.743Z

Link: CVE-2026-62593

cve-icon Vulnrichment

Updated: 2026-08-19T17:36:52.191Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:11.623

Modified: 2026-08-20T15:09:58.007

Link: CVE-2026-62593

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T09:30:09Z

Weaknesses