CVE-2026-62591: High severity Oracle Siebel CRM Integration (Oracle Siebel CRM) vulnerability
Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions that are affected are 25.12-26.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Integration accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An unauthenticated attacker with network access to the affected Open Integration component over HTTP can exploit it. The attacker does not need valid Siebel CRM credentials, but exploitation requires interaction by another person.
What is the potential impact of a successful attack?
A successful attack can give an attacker unauthorized access to critical data or all data accessible through Siebel CRM Integration. It can also allow unauthorized creation, deletion, or modification of that data.
Which versions are affected?
Affected supported versions are 25.12 through 26.6.