CVE-2026-62587: High severity Oracle Siebel CRM Administration vulnerability
Vulnerability in the Siebel CRM Administration product of Oracle Siebel CRM (component: Data Archival). Supported versions that are affected are 25.12-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Administration. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Administration accessible data as well as unauthorized update, insert or delete access to some of Siebel CRM Administration accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle Siebel CRM (Data Archival)to a version that resolves this vulnerability.Fixed in 25.12-26.6
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Organizations running Oracle Siebel CRM Administration with the Data Archival component on supported affected versions 25.12 through 26.6 are exposed. Exploitation requires network access over HTTP.
What level of access does an attacker need?
An attacker needs low-level privileges in Siebel CRM Administration and network access via HTTP. No user interaction is required, and the attack complexity is low.
What could a successful attacker do?
A successful attack can provide unauthorized access to critical data or all data accessible to Siebel CRM Administration. It can also permit unauthorized updates, inserts, or deletions to some accessible data.