CVE-2026-61326: High severity Oracle Siebel CRM Cloud Applications vulnerability
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data as well as unauthorized update, insert or delete access to some of Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker needs a low-privileged account and network access to the affected Siebel Cloud Manager component over HTTP. No user interaction is required, and the attack complexity is low.
Which deployments are affected?
Affected supported versions are 22.3 through 26.6 of Oracle Siebel CRM Cloud Applications. The provided information does not state whether any particular default configuration is affected.
What could a successful attacker do?
A successful attacker may obtain unauthorized access to critical data or all accessible Siebel CRM Cloud Applications data. They may also be able to update, insert, or delete some accessible data, and impacts may extend to additional products because the vulnerability has changed scope.
How can I determine whether my environment is exposed?
Identify whether Oracle Siebel CRM Cloud Applications is running a supported version from 22.3 through 26.6 and whether its Siebel Cloud Manager is reachable by potential low-privileged users over HTTP. The provided information does not include indicators of compromise or a detection method.