CVE-2026-60712: Medium severity Oracle Siebel CRM Cloud Applications vulnerability
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications. While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60712?
The severity of CVE-2026-60712 is rated as medium with a score of 6.5.
How do I fix CVE-2026-60712?
To fix CVE-2026-60712, apply the latest security patches provided by Oracle for the affected versions of Siebel CRM.
What are the affected versions in CVE-2026-60712?
The affected versions in CVE-2026-60712 range from 22.3 to 26.5 of Oracle Siebel CRM Cloud Applications.
Who can exploit CVE-2026-60712?
CVE-2026-60712 can be exploited by a low privileged attacker with logon access to the infrastructure where Siebel CRM Cloud Applications are deployed.
What components are affected by CVE-2026-60712?
CVE-2026-60712 specifically affects the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications.