Junglewise Threat Intelligence

CVE-2026-60712: Oracle Siebel CRM Cloud Applications information disclosure in Siebel Cloud Manager

CVE-2026-60712 · Severity: medium · CVSS 6.5 · Published 2026-07-21

Technologies: Oracle Siebel CRM Cloud Applications. Vendors: Oracle.

Executive brief

A security vulnerability exists in Oracle Siebel CRM Cloud Applications, specifically within the Cloud Manager component. An attacker who already has basic access to the underlying system infrastructure could exploit this flaw to gain unauthorized access to sensitive business data. This could lead to a significant breach of confidentiality across the CRM platform and potentially impact connected systems.

Technical details

A vulnerability in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications (versions 22.3 through 26.5) allows for unauthorized data access. The flaw is categorized by a scope change (S:C), meaning an exploit can impact resources beyond the immediate security scope of the Siebel application. The attack vector is local, requiring the attacker to have existing logon privileges to the infrastructure where the application executes. Successful exploitation results in high confidentiality impacts, potentially granting complete access to all accessible data within the CRM environment. The vulnerability is rated with a CVSS 3.1 base score of 6.5.

Affected products

  • Oracle Siebel CRM Cloud Applications 22.3-26.5

Timeline

  • 2026-07-21: advisory: Published by Oracle in the July 2026 Critical Patch Update
  • 2026-07-21: disclosed

References

Related threats