CVE-2026-61339: High severity Oracle Siebel CRM Cloud Applications vulnerability
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications. While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data as well as unauthorized update, insert or delete access to some of Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 7.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker needs a low-privileged account and logon access to the infrastructure where Siebel CRM Cloud Applications runs. No user interaction is required, and exploitation is rated as low complexity.
Which deployments are known to be affected?
Affected supported versions are 22.3 through 26.6 of Oracle Siebel CRM Cloud Applications, in the Siebel Cloud Manager component.
What could a successful attacker access or change?
Successful exploitation can provide unauthorized access to critical data or complete access to all accessible Siebel CRM Cloud Applications data. It can also allow unauthorized update, insert, or delete operations on some accessible data.
Can the impact extend beyond the vulnerable application?
Yes. The CVSS scope is changed, and the vulnerability may significantly affect additional products even though it resides in Siebel CRM Cloud Applications.