SYS::ONLINE
Wasteland.
Briefs1482
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60711 2026-07-21

CVE-2026-60711: Critical Siebel CRM Cloud Applications Takeover Flaw (CVSS 9.9)

"Oracle has disclosed a critical, network-exploitable vulnerability in Siebel CRM Cloud Applications that allows a low-privileged attacker to fully take over the product and impact adjacent systems."

Oracle has disclosed a critical, network-exploitable vulnerability in Siebel CRM Cloud Applications that allows a low-privileged attacker to fully take over the product and impact adjacent systems.

What Is It

CVE-2026-60711 is a critical vulnerability in the Siebel Cloud Manager component of Oracle's Siebel CRM Cloud Applications. Per Oracle, the flaw is "easily exploitable" and allows a low-privileged attacker with network access via HTTP to compromise the product. Successful attacks can result in a complete takeover of Siebel CRM Cloud Applications.

The vulnerability carries a CVSS 3.1 base score of 9.9 (Critical), with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, indicating network attack vector, low complexity, low privileges required, no user interaction, and high impact to confidentiality, integrity, and availability.

Why It Matters

A key aggravating factor is scope change: while the vulnerability resides in Siebel CRM Cloud Applications, Oracle warns that "attacks may significantly impact additional products." This means a successful exploit is not contained to the CRM platform alone and may cascade into other connected systems.

Combined with low attack complexity, no required user interaction, and only low privileges needed, this vulnerability presents a high-value target for attackers seeking full compromise of enterprise CRM environments.

What's Vulnerable

Patch Status

Oracle addressed this vulnerability in its July 2026 Critical Patch Update (CPU). Organizations running affected versions (22.3–26.5) should apply the fixes referenced in the Oracle Critical Patch Update advisory as a priority given the critical severity and low exploitation barrier.

No CISA KEV entry was supplied for this CVE, so active exploitation is not confirmed by KEV at this time.

Sources