Junglewise Threat Intelligence

CVE-2026-60689: Oracle Siebel CRM information disclosure in Siebel Cloud Manager

CVE-2026-60689 · Severity: high · CVSS 7.5 · Published 2026-07-21

Technologies: Oracle Siebel CRM Cloud Applications. Vendors: Oracle.

Executive brief

A vulnerability in the Oracle Siebel Cloud Manager component allows unauthorized individuals to access sensitive business data. This component is used to manage Siebel CRM deployments in cloud environments. An attacker could exploit this over the network without needing a username or password, potentially leading to the exposure of all customer and corporate data stored within the CRM system.

Technical details

A vulnerability in the Siebel Cloud Manager component of Oracle Siebel CRM (versions 22.3-26.5) allows an unauthenticated attacker with network access via HTTP to compromise the application. The flaw is described as easily exploitable and does not require user interaction. Successful exploitation results in a high confidentiality impact, granting the attacker unauthorized access to critical data or complete access to all data accessible via the Siebel CRM Cloud Applications. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Siebel CRM Cloud Applications 22.3-26.5

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats