CVE-2026-60753: High severity Oracle Siebel CRM Deployment (Installation) vulnerability
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Installation). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Deployment executes to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
Who is realistically able to exploit this vulnerability?
Systems running affected supported versions 17.0 through 26.6 are exposed when an attacker can log on to the infrastructure where Siebel CRM Deployment executes. The CVSS vector identifies the attack as local, so it is not described as remotely exploitable without such access.
What access is required for exploitation?
An attacker needs low-privileged credentials or another means of logging on to the infrastructure hosting Siebel CRM Deployment. No user interaction is required, and the attack complexity is rated low.
What is the potential impact if exploitation succeeds?
Successful exploitation can result in takeover of Siebel CRM Deployment, with high confidentiality, integrity, and availability impact. This could allow exposure or modification of data and disruption of the affected deployment component.
How can I determine whether my environment is affected?
Identify installations of Oracle Siebel CRM Deployment using the Installation component and determine whether their supported version falls between 17.0 and 26.6. Also review which low-privileged accounts can log on to the infrastructure where the deployment executes.