CVE-2026-62595: High severity Oracle Oracle Siebel CRM (Open Integration) vulnerability
Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions that are affected are 25.12-26.6. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Siebel CRM Integration executes to compromise Siebel CRM Integration. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Integration accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
Affected Software
Event History
Frequently Asked Questions
Who is exposed to exploitation?
Instances of the Open Integration component in supported Oracle Siebel CRM Integration versions 25.12 through 26.6 are affected when an attacker can access the physical communication segment connected to the hardware running the component.
Does exploitation require an authenticated Siebel CRM account or user interaction?
No. The vulnerability is unauthenticated and requires no user interaction, but the attacker must have access to the relevant adjacent physical communication segment.
What could a successful attacker do?
An attacker could obtain unauthorized access to critical data or all data accessible to Siebel CRM Integration, and could create, delete, or modify critical data or all accessible data. The stated impacts are confidentiality and integrity; availability impact is not identified.