CVE-2026-70949: High severity Oracle Oracle Siebel CRM vulnerability
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Oracle Siebel CRM Deployment installations using the Server Infrastructure component on supported versions 17.0 through 26.6 are affected. Exposure requires that an attacker can reach the deployment environment over HTTP.
What level of access does an attacker need?
An attacker needs network access via HTTP and low-privileged credentials. No user interaction is required, and the stated attack complexity is low.
What is the likely impact of successful exploitation?
Successful exploitation can result in takeover of Siebel CRM Deployment. The vulnerability has high confidentiality, integrity, and availability impact.