Junglewise Threat Intelligence

CVE-2026-70859: Oracle Siebel CRM Integration privilege escalation in REST

CVE-2026-70859 · Severity: high · CVSS 8.5 · Published 2026-08-18

Technologies: Oracle Siebel CRM, Oracle Siebel CRM Integration. Vendors: Oracle.

Executive brief

Oracle Siebel CRM Integration is a core component of Siebel CRM that handles API communication. A low-privileged attacker with network access can exploit a difficult-to-exploit vulnerability in the REST component to gain complete control of the Siebel CRM Integration system, potentially compromising customer data and business operations across integrated systems.

Technical details

This is a privilege escalation vulnerability in the REST component of Oracle Siebel CRM Integration affecting versions 17.0 through 26.6. The vulnerability requires low privileges and network access via HTTP, but is difficult to exploit (high attack complexity). Successful exploitation allows an attacker to achieve complete system compromise (confidentiality, integrity, and availability impacts) with scope change, meaning the attack can impact other connected systems beyond Siebel CRM Integration itself. No public exploit evidence is known at this time.

Affected products

  • Oracle Siebel CRM Integration 17.0–26.6

Timeline

  • 2026-08-18: disclosed

References

Related threats