CVE-2026-60751

8.8

Oracle · Siebel Apps - Marketing

A vulnerability in the Marketing component of Oracle Siebel CRM allows a low privileged attacker with network access to compromise the application.

Executive summary

An authenticated network-based vulnerability in Oracle Siebel CRM allows attackers to achieve full system takeover, warranting immediate remediation.

Vulnerability

This is a highly exploitable vulnerability where an attacker with low-level privileges can leverage network access via HTTP to gain unauthorized control over the Siebel Apps - Marketing component.

Business impact

Successful exploitation of this vulnerability leads to a complete takeover of the Siebel Apps - Marketing application, which may result in unauthorized access to sensitive customer data, loss of data integrity, and significant operational disruption. Given the CVSS score of 8.8, this flaw represents a high risk to business continuity and data security for organizations utilizing the CRM platform.

Remediation

Immediate Action: Update the affected Oracle Siebel CRM installation to the version specified in the August 2026 Oracle Security Alert.

Proactive Monitoring: Review application access logs for unusual HTTP traffic patterns or unauthorized attempts to access administrative functions within the Marketing module.

Compensating Controls: Deploy Web Application Firewall (WAF) rules to filter suspicious inbound traffic and restrict network access to the application to trusted segments.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The high CVSS score of 8.8 underscores the urgency of this update. Administrators should prioritize patching the Siebel CRM environment immediately to prevent potential system compromise and unauthorized data access.

More Oracle CVEs