CVE-2026-62454: High severity Oracle Siebel CRM Cloud Applications vulnerability
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict access to the Siebel CRM Cloud Applications environment so that only authorized users/systems can log on to the infrastructure where Siebel CRM Cloud Applications executes, reducing exposure to low-privileged authenticated attackers.
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker needs a low-privileged account and logon access to the infrastructure where Siebel CRM Cloud Applications runs. The attack is local and does not require user interaction.
Which deployments are known to be affected?
Supported Oracle Siebel CRM Cloud Applications versions 22.3 through 26.6 are affected, specifically in the Siebel Cloud Manager component.
What is the potential impact of successful exploitation?
A successful attack can result in takeover of Siebel CRM Cloud Applications, with high impacts to confidentiality, integrity, and availability.