Unauthenticated Network Vulnerability in Oracle Siebel CRM Integration
CVE-2026-62589

8.7HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-62589?

A vulnerability exists in the Siebel CRM Integration component of Oracle Siebel CRM, impacting supported versions 25.12 through 26.6. This vulnerability allows an unauthenticated attacker with network access via HTTP to potentially compromise the integration, impacting not just Siebel CRM Integration but also other connected products. Successful exploitation could lead to unauthorized creation, deletion, or modification of critical data accessible through Siebel CRM Integration, posing significant risks to data confidentiality and integrity. Organizations using the affected versions are strongly advised to apply necessary security measures to mitigate the threat.

Affected Version(s)

Siebel CRM Integration 25.12 <= 26.6

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.