CVE-2026-60798: High severity Oracle Siebel CRM Deployment (Migration) vulnerability
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Migration). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. While the vulnerability is in Siebel CRM Deployment, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data as well as unauthorized update, insert or delete access to some of Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
Oracle Siebel CRM Deployment installations using the Migration component are affected if they are on supported versions 17.0 through 26.6.
What level of access does an attacker need?
An attacker needs low-privileged access and network reachability to the HTTP interface. No user interaction is required, and exploitation is rated low complexity.
What could a successful attacker do?
A successful attack can expose critical data or all data accessible to Siebel CRM Deployment. It can also permit unauthorized updates, inserts, or deletions of some accessible data, and may significantly affect additional products because the vulnerability has scope change.