CVE-2026-62593: High severity Oracle Siebel CRM Integration (Open Integration) vulnerability
Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions that are affected are 25.12-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Integration. While the vulnerability is in Siebel CRM Integration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
Who is able to exploit this vulnerability?
An attacker needs network access to the affected Open Integration component over HTTP and low-level privileges. No user interaction is required.
Which deployments are affected?
The affected supported versions are 25.12 through 26.6 of Oracle Siebel CRM Integration's Open Integration component. The provided information does not state whether the component is enabled or exposed by default.
What is the likely impact of successful exploitation?
Successful exploitation can provide unauthorized access to critical data or complete access to all data accessible to Siebel CRM Integration. Because the vulnerability has scope change, attacks may also significantly affect additional products.