CVE-2026-60758: High severity Oracle Siebel Artificial Intelligence vulnerability
Vulnerability in the Siebel Artificial Intelligence product of Oracle Siebel CRM (component: AI). Supported versions that are affected are 25.12-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Artificial Intelligence. While the vulnerability is in Siebel Artificial Intelligence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel Artificial Intelligence accessible data as well as unauthorized update, insert or delete access to some of Siebel Artificial Intelligence accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
Oracle Siebel Artificial Intelligence supported versions 25.12 through 26.6 are affected. The vulnerable component is AI within Oracle Siebel CRM.
What access does an attacker need to exploit this issue?
An attacker needs network access to the affected service over HTTP and a low-privileged account. No user interaction is required, and the attack complexity is low.
What could a successful attacker do?
A successful attack can expose critical data or all data accessible to Siebel Artificial Intelligence. It can also permit unauthorized update, insert, or delete operations on some accessible data, and may significantly affect additional products because the vulnerability has scope change.