CVE-2026-60767

8.8

Oracle · Siebel Apps - Marketing

A vulnerability in the Marketing component of Oracle Siebel CRM allows a low privileged attacker with network access to compromise the application.

Executive summary

An authenticated network-based vulnerability in Oracle Siebel CRM allows attackers to achieve full system takeover, warranting immediate remediation.

Vulnerability

This is a highly exploitable vulnerability where an attacker with low-level privileges can leverage network access via HTTP to gain unauthorized control over the Siebel Apps - Marketing component.

Business impact

Exploitation of this vulnerability allows for the complete takeover of the Siebel Apps - Marketing application, posing a severe risk of data exfiltration and unauthorized modification of CRM records. With a CVSS score of 8.8, the vulnerability demands prompt attention to protect the confidentiality and integrity of critical business systems.

Remediation

Immediate Action: Update the affected Oracle Siebel CRM installation to the version specified in the August 2026 Oracle Security Alert.

Proactive Monitoring: Monitor server logs for anomalous activity or unexpected authentication patterns directed at the Marketing module.

Compensating Controls: Utilize a Web Application Firewall to monitor and block malicious HTTP requests that match known exploitation patterns.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Organizations should treat this high-severity vulnerability with urgency. Apply the vendor-provided security updates as soon as possible to mitigate the risk of unauthorized system access.

More Oracle CVEs