Junglewise Threat Intelligence

CVE-2026-60713: Oracle Siebel CRM data compromise in Siebel Cloud Manager

CVE-2026-60713 · Severity: medium · CVSS 4.4 · Published 2026-07-21

Technologies: Oracle Siebel CRM Cloud Applications. Vendors: Oracle, Oracle Corporation.

Executive brief

A vulnerability exists in Oracle Siebel Cloud Manager, a tool used to manage Siebel CRM deployments in cloud environments. An attacker with low-level access to the underlying server infrastructure can exploit this flaw to view, modify, or delete sensitive business data. While the attack requires an existing foothold on the system, it could lead to unauthorized data manipulation and a breach of confidentiality for customer records.

Technical details

This vulnerability affects the Siebel Cloud Manager component within Oracle Siebel CRM Cloud Applications versions 22.3 through 26.5. It is classified as an easily exploitable flaw that requires the attacker to have local logon privileges to the infrastructure where the application executes (Attack Vector: Local). A successful exploit allows a low-privileged user to perform unauthorized read, update, insert, or delete operations on a subset of the application's data. The vulnerability has a CVSS 3.1 base score of 4.4, reflecting impacts on confidentiality and integrity without affecting system availability.

Affected products

  • Oracle Corporation Siebel CRM Cloud Applications 22.3-26.5

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD record published

References

Related threats