Junglewise Threat Intelligence

CVE-2026-60705: Oracle Siebel CRM Cloud Applications security bypass in Siebel Cloud Manager

CVE-2026-60705 · Severity: high · CVSS 7 · Published 2026-07-21

Technologies: Oracle Siebel CRM Cloud Applications. Vendors: Oracle.

Executive brief

Oracle Siebel CRM Cloud Applications, a platform used by businesses to manage customer relationships and sales data, contains a vulnerability in its Cloud Manager component. An unauthenticated attacker could exploit this flaw over the network to gain unauthorized access to sensitive customer information or disrupt business operations. Successful exploitation could lead to the theft of critical data, unauthorized modification of records, or a partial shutdown of the CRM service.

Technical details

A vulnerability exists in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications (versions 22.3 through 26.5). The flaw is exploitable by an unauthenticated attacker with network access via HTTP, though Oracle notes the attack complexity is high. Successful exploitation allows for unauthorized access to critical data, the ability to update or delete certain records, and the potential to cause a partial denial of service (DoS). The vulnerability has a CVSS 3.1 base score of 7.0, reflecting high confidentiality impact but lower integrity and availability impacts. Users should refer to the Oracle July 2026 Critical Patch Update for remediation guidance.

Affected products

  • Oracle Siebel CRM Cloud Applications 22.3-26.5

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-60705 by Oracle
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released

References

Related threats