CVE-2026-61341: High severity Oracle Siebel CRM Cloud Applications vulnerability
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Mitigate exposure by restricting network access to Siebel CRM Cloud Applications over HTTP (AV:N) so low-privileged remote attackers cannot reach the Siebel Cloud Manager component.
Event History
Frequently Asked Questions
Which deployments are affected?
Oracle identifies supported Siebel CRM Cloud Applications versions 22.3 through 26.6 as affected, specifically in the Siebel Cloud Manager component.
What level of access does an attacker need?
An attacker needs network access to the target over HTTP and low-privileged credentials. No user interaction is required, and the vulnerability is described as easily exploitable.
What is the potential impact of successful exploitation?
Successful exploitation can result in takeover of Siebel CRM Cloud Applications, with high confidentiality, integrity, and availability impact.