Junglewise Threat Intelligence

CVE-2026-60711: Oracle Siebel CRM full compromise in Siebel Cloud Manager

CVE-2026-60711 · Severity: critical · CVSS 9.9 · Published 2026-07-21

Technologies: Oracle Siebel CRM Cloud Applications. Vendors: Oracle.

Executive brief

A critical vulnerability exists in Oracle Siebel Cloud Manager, a tool used to manage and deploy Siebel CRM environments in the cloud. An attacker with basic user credentials can exploit this flaw over the network to gain full control of the application. This could lead to a total compromise of customer data, service outages, and potential unauthorized access to connected corporate systems.

Technical details

This vulnerability affects the Siebel Cloud Manager component within Oracle Siebel CRM Cloud Applications versions 22.3 through 26.5. It is classified as easily exploitable, requiring only low-privileged authentication and network access via HTTP. The flaw is notable for a 'scope change' (Status: C), meaning a successful exploit allows an attacker to move beyond the Siebel application to impact other parts of the infrastructure. Successful exploitation results in a complete takeover of the Siebel CRM Cloud Applications environment, impacting confidentiality, integrity, and availability. Oracle addressed this in the July 2026 Critical Patch Update.

Affected products

  • Oracle Siebel CRM Cloud Applications 22.3-26.5

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released

References

Related threats