Description
Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions that are affected are 25.12-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Integration. While the vulnerability is in Siebel CRM Integration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data as well as unauthorized update, insert or delete access to some of Siebel CRM Integration accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
Published: 2026-08-18
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in the Open Integration component of Oracle Siebel CRM Integration that can be exploited by an attacker with low privileges and network access through HTTP. The exploit allows the attacker to read critical data and perform unauthorized updates, inserts or deletions, thereby breaching confidentiality and partially affecting integrity. The CVSS 3.1 vector indicates a high confidentiality impact and a low integrity impact, with a base score of 8.5.

Affected Systems

The affected asset is Oracle Siebel CRM Integration, specifically the Open Integration component within versions 25.12 through 26.6. The vulnerability may also indirectly affect other products that rely on Siebel CRM Integration, expanding its potential impact beyond the primary scope.

Risk and Exploitability

With an AV:N attack vector, AC:L and PR:L, the vulnerability is considered easily exploitable. Although the EPSS score is not available, the absence of KEV listing does not lessen the urgency. The low privileged attacker only needs network connectivity to the HTTP interface, a common entry point in many environments, which raises the risk of successful exploitation. The potential to read and modify sensitive data, coupled with the relatively high CVSS score, warrants immediate attention.

Generated by OpenCVE AI on August 19, 2026 at 11:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch for Siebel CRM Integration 25.12 to 26.6 as detailed in the security alert
  • Restrict HTTP access to the Open Integration component to trusted network segments or enforce strict authentication to prevent unauthorized reach
  • Disable or remove the Open Integration component if it is not required for business operations
  • Enable comprehensive logging for all data modification activities and monitor for anomalous behavior

Generated by OpenCVE AI on August 19, 2026 at 11:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Oracle siebel Crm
CPEs cpe:2.3:a:oracle:siebel_crm:*:*:*:*:*:*:*:*
Vendors & Products Oracle siebel Crm

Thu, 20 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access and Modification via Open Integration Component
Weaknesses CWE-200
CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions that are affected are 25.12-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Integration. While the vulnerability is in Siebel CRM Integration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data as well as unauthorized update, insert or delete access to some of Siebel CRM Integration accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
First Time appeared Oracle
Oracle siebel Crm Integration
CPEs cpe:2.3:a:oracle:siebel_crm_integration:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Integration
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Oracle Siebel Crm Siebel Crm Integration
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T03:56:26.597Z

Reserved: 2026-07-14T14:54:48.743Z

Link: CVE-2026-62596

cve-icon Vulnrichment

Updated: 2026-08-19T17:39:00.379Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:11.970

Modified: 2026-08-20T15:09:45.490

Link: CVE-2026-62596

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T12:00:05Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control