CVE-2026-62589: High severity Oracle Siebel CRM Integration vulnerability
Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions that are affected are 25.12-26.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration. While the vulnerability is in Siebel CRM Integration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Integration accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Organizations using Oracle Siebel CRM Integration with the Open Integration component on supported affected versions 25.12 through 26.6 are exposed if an attacker can reach the service over HTTP.
Does exploitation require an authenticated account or user interaction?
No. The vulnerability can be exploited by an unauthenticated attacker with network access via HTTP, and it does not require user interaction. Exploitation is described as difficult, reflected by the high attack-complexity rating.
What could a successful attacker do?
A successful attack can provide unauthorized access to critical data or all data accessible to Siebel CRM Integration. It can also allow unauthorized creation, deletion, or modification of critical data or all accessible integration data.
Can the impact extend beyond Siebel CRM Integration?
Yes. The vulnerability has a scope change, meaning successful attacks may significantly affect additional products beyond the vulnerable Siebel CRM Integration component.