CVE-2026-60767: High severity Oracle Siebel Apps - Marketing vulnerability
Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this vulnerability can result in takeover of Siebel Apps - Marketing. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Deployments of Oracle Siebel Apps - Marketing running supported versions 17.0 through 26.6 are affected. The vulnerable component is Marketing.
What does an attacker need to exploit it?
An attacker needs network access to the affected product over HTTP and low-privileged credentials. No user interaction is required, and exploitation is rated as low complexity.
What is the potential impact of successful exploitation?
Successful exploitation can result in takeover of Siebel Apps - Marketing. The stated impacts include high compromise of confidentiality, integrity, and availability.