CVE-2026-60767
8.8Oracle · Siebel Apps - Marketing
A vulnerability in the Marketing component of Oracle Siebel CRM allows a low privileged attacker with network access to compromise the application.
Executive summary
An authenticated network-based vulnerability in Oracle Siebel CRM allows attackers to achieve full system takeover, warranting immediate remediation.
Vulnerability
This is a highly exploitable vulnerability where an attacker with low-level privileges can leverage network access via HTTP to gain unauthorized control over the Siebel Apps - Marketing component.
Business impact
Exploitation of this vulnerability allows for the complete takeover of the Siebel Apps - Marketing application, posing a severe risk of data exfiltration and unauthorized modification of CRM records. With a CVSS score of 8.8, the vulnerability demands prompt attention to protect the confidentiality and integrity of critical business systems.
Remediation
Immediate Action: Update the affected Oracle Siebel CRM installation to the version specified in the August 2026 Oracle Security Alert.
Proactive Monitoring: Monitor server logs for anomalous activity or unexpected authentication patterns directed at the Marketing module.
Compensating Controls: Utilize a Web Application Firewall to monitor and block malicious HTTP requests that match known exploitation patterns.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Organizations should treat this high-severity vulnerability with urgency. Apply the vendor-provided security updates as soon as possible to mitigate the risk of unauthorized system access.