Description
Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions that are affected are 25.12-26.6. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel CRM Integration. While the vulnerability is in Siebel CRM Integration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Integration accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Integration. CVSS 3.1 Base Score 7.7 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:H).
Published: 2026-08-18
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in the Open Integration component of Oracle Siebel CRM Integration that allows a high‑privileged attacker with network access via HTTP to create, delete, or modify critical data and to repeatedly crash the service. The flaw provides integrity and availability impacts, as indicated by a CVSS 3.1 base score of 7.7 and an availability impact of complete denial of service.

Affected Systems

Oracle Siebel CRM Integration, versions 25.12 to 26.6 inclusive, are affected. The vulnerability is present only in the Open Integration component and is reachable through standard HTTP interfaces.

Risk and Exploitability

The CVSS score of 7.7 reflects a high severity attack that requires high privileges and network access, but the description notes that exploiting the flaw is difficult. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog. Because the flaw can change scope and affect additional products, the potential impact extends beyond the immediate component if the attacker gains sufficient privilege or access. The attack vector is inferred to be remote network access over HTTP, exploiting a privilege‑management flaw that permits unauthorized operation of the integration service.

Generated by OpenCVE AI on August 19, 2026 at 11:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Siebel CRM Integration patch or upgrade to a version that is not affected.
  • Restrict HTTP access to the Open Integration component by firewall or VPN, allowing only trusted, privileged users to reach the interface.
  • Enforce strong authentication and granular role‑based access controls on the Siebel CRM Integration service to prevent unauthorized data operations.

Generated by OpenCVE AI on August 19, 2026 at 11:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Oracle siebel Crm
CPEs cpe:2.3:a:oracle:siebel_crm:*:*:*:*:*:*:*:*
Vendors & Products Oracle siebel Crm

Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Title High Privilege HTTP Attack Enabling Unauthorized Data Manipulation and DoS in Oracle Siebel CRM Integration
Weaknesses CWE-269
CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions that are affected are 25.12-26.6. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel CRM Integration. While the vulnerability is in Siebel CRM Integration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Integration accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Integration. CVSS 3.1 Base Score 7.7 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:H).
First Time appeared Oracle
Oracle siebel Crm Integration
CPEs cpe:2.3:a:oracle:siebel_crm_integration:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Integration
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:H'}


Subscriptions

Oracle Siebel Crm Siebel Crm Integration
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T16:36:01.744Z

Reserved: 2026-07-14T14:54:48.743Z

Link: CVE-2026-62594

cve-icon Vulnrichment

Updated: 2026-08-20T16:35:57.978Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:11.740

Modified: 2026-08-21T15:02:14.147

Link: CVE-2026-62594

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T12:00:05Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control