CVE-2026-62592: Critical severity Oracle Siebel CRM Integration (Open Integration) vulnerability
Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions that are affected are 25.12-26.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration. Successful attacks of this vulnerability can result in takeover of Siebel CRM Integration. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Deployments of Oracle Siebel CRM Integration using the Open Integration component are affected if they run a supported version from 25.12 through 26.6 and are reachable over HTTP from an attacker’s network location.
Does exploitation require authentication or user interaction?
No. The vulnerability is described as easily exploitable by an unauthenticated attacker with network access via HTTP, with no user interaction required.
What is the potential impact of a successful attack?
A successful attack can result in takeover of Siebel CRM Integration, with high confidentiality, integrity, and availability impact.