Oracle has disclosed a critical, network-exploitable vulnerability in Siebel CRM Cloud Applications that allows a low-privileged attacker to fully take over the product and impact adjacent systems.
What Is It
CVE-2026-60711 is a critical vulnerability in the Siebel Cloud Manager component of Oracle's Siebel CRM Cloud Applications. Per Oracle, the flaw is "easily exploitable" and allows a low-privileged attacker with network access via HTTP to compromise the product. Successful attacks can result in a complete takeover of Siebel CRM Cloud Applications.
The vulnerability carries a CVSS 3.1 base score of 9.9 (Critical), with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, indicating network attack vector, low complexity, low privileges required, no user interaction, and high impact to confidentiality, integrity, and availability.
Why It Matters
A key aggravating factor is scope change: while the vulnerability resides in Siebel CRM Cloud Applications, Oracle warns that "attacks may significantly impact additional products." This means a successful exploit is not contained to the CRM platform alone and may cascade into other connected systems.
Combined with low attack complexity, no required user interaction, and only low privileges needed, this vulnerability presents a high-value target for attackers seeking full compromise of enterprise CRM environments.
What's Vulnerable
- Vendor: Oracle Corporation
- Product: Siebel CRM Cloud Applications
- Component: Siebel Cloud Manager
- Affected versions: 22.3 through 26.5
Patch Status
Oracle addressed this vulnerability in its July 2026 Critical Patch Update (CPU). Organizations running affected versions (22.3–26.5) should apply the fixes referenced in the Oracle Critical Patch Update advisory as a priority given the critical severity and low exploitation barrier.
No CISA KEV entry was supplied for this CVE, so active exploitation is not confirmed by KEV at this time.