Vulnerability in Oracle Siebel CRM Deployment Allows Unauthorized Access
CVE-2026-70856

7.5HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-70856?

An important security vulnerability exists in Oracle's Siebel CRM Deployment product. This weakness allows an unauthenticated attacker with network access via HTTP to potentially compromise the system. Exploiting this vulnerability requires human interaction from an individual other than the attacker, which introduces a layer of complexity. Malicious actors could leverage this flaw to take control of the Siebel CRM Deployment, leading to exposure of sensitive data and disruption of services. Organizations using affected versions (17.0 through 26.6) are advised to take immediate action to implement the necessary security updates.

Affected Version(s)

Siebel CRM Deployment 17.0 <= 26.6

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.