CVE-2026-62585: Critical severity Oracle Siebel CRM Administration vulnerability
Vulnerability in the Siebel CRM Administration product of Oracle Siebel CRM (component: Data Archival). Supported versions that are affected are 25.12-26.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Administration. Successful attacks of this vulnerability can result in takeover of Siebel CRM Administration. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle Siebel CRM (Data Archival)to a version that resolves this vulnerability.Fixed in 25.12-26.6
Event History
Frequently Asked Questions
Which deployments are exposed to this vulnerability?
Oracle Siebel CRM Administration deployments using the Data Archival component on supported versions 25.12 through 26.6 are affected. Exposure requires network access to the affected service over HTTP.
Does an attacker need credentials or user interaction to exploit it?
No. The vulnerability is described as easily exploitable by an unauthenticated attacker with network access via HTTP, and it requires no user interaction.
What could a successful attack allow?
Successful exploitation can result in takeover of Siebel CRM Administration, with high impacts to confidentiality, integrity, and availability.