Vulnerability in Siebel CRM Deployment by Oracle allowing unauthorized data access
CVE-2026-60798

8.5HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-60798?

A vulnerability found in Oracle's Siebel CRM Deployment component enables low-privileged attackers with network access via HTTP to exploit the system. This flaw can lead to unauthorized access to sensitive data and allow for manipulation of data through update, insert, or delete actions. Although the main issue lies within the Siebel CRM Deployment, the implications can affect additional products, potentially compromising critical information and disrupting integral operations.

Affected Version(s)

Siebel CRM Deployment 17.0 <= 26.6

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.