Junglewise Threat Intelligence

CVE-2026-60709: Oracle Siebel CRM data manipulation in Siebel Cloud Manager

CVE-2026-60709 · Severity: medium · CVSS 4.2 · Published 2026-07-21

Technologies: Oracle Siebel CRM Cloud Applications. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle Siebel Cloud Manager, a tool used to manage Siebel CRM deployments in cloud environments. An attacker with access to the local network segment where the software is running could potentially view or modify a limited amount of sensitive business data. While the impact is restricted to specific subsets of data, it could lead to unauthorized changes or information disclosure within the CRM system.

Technical details

A vulnerability in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications (versions 22.3 through 26.5) allows for unauthorized data access. The exploit requires the attacker to be positioned on the same physical or logical communication segment (Adjacent vector) as the target hardware. The attack complexity is rated as high, suggesting specific conditions or timing are required for a successful compromise. If successful, an unauthenticated attacker can perform unauthorized read, update, insert, or delete operations on a subset of the data accessible to the Siebel CRM Cloud Applications.

Affected products

  • Oracle Siebel CRM Cloud Applications 22.3-26.5

Timeline

  • 2026-07-21: advisory: Published by Oracle in the July 2026 Critical Patch Update

References

Related threats