CVE-2026-62586: High severity Oracle Siebel CRM Administration vulnerability
Vulnerability in the Siebel CRM Administration product of Oracle Siebel CRM (component: Data Archival). Supported versions that are affected are 25.12-26.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Administration. While the vulnerability is in Siebel CRM Administration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Administration accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
Affected supported versions are 25.12 through 26.6 of Oracle Siebel CRM Administration, specifically the Data Archival component.
Does exploitation require authentication or user interaction?
No. An unauthenticated attacker with network access over HTTP can exploit the vulnerability, and no user interaction is required.
What is the likely impact of successful exploitation?
Successful exploitation can allow unauthorized access to critical data or complete access to all data accessible through Siebel CRM Administration. The scope change indicates attacks may also significantly affect additional products.