Junglewise Threat Intelligence

CVE-2026-70856: Oracle Siebel CRM Deployment client-side attack via HTTP

CVE-2026-70856 · Severity: high · CVSS 7.5 · Published 2026-08-18

Technologies: Oracle Siebel CRM. Vendors: Oracle.

Executive brief

Oracle Siebel CRM is a customer relationship management system used by enterprises to manage sales, marketing, and service operations. A network-accessible vulnerability in the Siebel CRM Deployment component allows an unauthenticated attacker to compromise the system through a specially crafted HTTP request if a user visits or interacts with an attacker-controlled page. A successful exploit could result in complete takeover of the Siebel CRM Deployment system, potentially exposing sensitive customer and business data.

Technical details

This vulnerability in the Migration component of Oracle Siebel CRM Deployment allows unauthenticated attackers with network access to exploit the system via HTTP. The attack is difficult to exploit and requires user interaction (indicated by the AC:H and UI:R parameters), meaning a victim must be socially engineered or tricked into visiting an attacker-controlled resource. Successful exploitation results in complete compromise of the affected Siebel CRM Deployment system, affecting confidentiality, integrity, and availability. The vulnerability impacts versions 17.0 through 26.6 of Siebel CRM. Patches or fixes should be available through Oracle's regular security updates; check Oracle's security advisory for mitigation guidance.

Affected products

  • Oracle Siebel CRM 17.0-26.6

Timeline

  • 2026-08-18: disclosed
  • 2026-08-18: advisory

References

Related threats