CVE-2026-70859: High severity Oracle Siebel CRM Integration vulnerability
Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Integration. While the vulnerability is in Siebel CRM Integration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Siebel CRM Integration. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
Who is realistically exposed to this vulnerability?
Organizations running Oracle Siebel CRM Integration versions 17.0 through 26.6 with the REST component reachable over HTTP are affected. Exploitation requires network access and a low-privileged account.
Does exploitation require user interaction or administrative privileges?
No user interaction is required, and the attacker does not need administrative privileges. The stated prerequisite is a low-privileged attacker with network access via HTTP.
What is the potential impact if exploitation succeeds?
A successful attack can result in takeover of Siebel CRM Integration, with high confidentiality, integrity, and availability impact. The vulnerability has scope change, so attacks may also significantly affect additional products.
Is exploitation expected to be straightforward?
No. The vulnerability is rated as difficult to exploit, reflected by the high attack-complexity metric, although it remains network-accessible and requires only low privileges.