CVE-2026-60754: Critical severity Oracle Siebel Apps - Marketing vulnerability
Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel Apps - Marketing accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel Apps - Marketing. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed?
Oracle Siebel Apps - Marketing deployments running supported versions 17.0 through 26.6 are affected if an attacker can reach the product over HTTP.
Does exploitation require credentials or user interaction?
No. The vulnerability is exploitable by an unauthenticated attacker with network access via HTTP, with no user interaction required.
What could a successful attack achieve?
An attacker could obtain unauthorized access to critical data or all data accessible to Siebel Apps - Marketing. They could also cause the application to hang or repeatedly crash, resulting in complete denial of service.