CVE-2026-61332: High severity Oracle Siebel CRM Cloud Applications vulnerability
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.6. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Cloud Applications accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N).
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker needs high privileges in Oracle Siebel CRM Cloud Applications and network access to the affected Siebel Cloud Manager component over HTTP. No user interaction is required, and the attack complexity is low.
Which deployments are affected?
Affected supported versions are 22.3 through 26.6 of Oracle Siebel CRM Cloud Applications. The provided information does not state whether any particular deployment configuration changes exposure.
What could a successful attacker do?
A successful attacker could create, delete, or modify critical data or all accessible Siebel CRM Cloud Applications data, and could gain access to critical data or complete access to accessible application data. The vulnerability may also significantly affect additional products because its scope can change.