Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cspuaug2026.html |
|
History
Wed, 02 Sep 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oracle siebel Crm
|
|
| CPEs | cpe:2.3:a:oracle:siebel_crm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle siebel Crm
|
Fri, 21 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Low-Privilege HTTP Exploit Enables Full Application Takeover in Oracle Siebel CRM Cloud Manager |
Fri, 21 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote takeover of Oracle Siebel CRM Cloud Applications via low‑privilege HTTP exploitation | |
| Weaknesses | CWE-77 |
Wed, 19 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 19 Aug 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote takeover of Oracle Siebel CRM Cloud Applications via low‑privilege HTTP exploitation | |
| Weaknesses | CWE-284 CWE-77 |
Tue, 18 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). | |
| First Time appeared |
Oracle
Oracle siebel Crm Cloud Applications |
|
| CPEs | cpe:2.3:a:oracle:siebel_crm_cloud_applications:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle siebel Crm Cloud Applications |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published: 2026-08-18T21:00:05.190Z
Updated: 2026-08-20T03:56:53.197Z
Reserved: 2026-07-08T15:52:20.747Z
Link: CVE-2026-61317
Updated: 2026-08-19T19:49:31.836Z
Status : Analyzed
Published: 2026-08-18T21:16:59.737
Modified: 2026-09-02T17:35:28.727
Link: CVE-2026-61317
No data.