CVE-2026-60754 is a CVSS 9.1 vulnerability in Oracle Siebel CRM's Siebel Apps - Marketing product that lets an unauthenticated remote attacker read all accessible data or crash the application outright. The record was published to NVD on 2026-08-18.
What Is It
A critical vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM, in the Marketing component. Oracle describes it as easily exploitable: an unauthenticated attacker with network access via HTTP can compromise Siebel Apps - Marketing with no privileges and no user interaction required.
Successful exploitation results in unauthorized access to critical data, up to complete access to all Siebel Apps - Marketing accessible data, and the unauthorized ability to cause a hang or frequently repeatable crash, a complete denial of service.
Why It Matters
The CVSS 3.1 base score is 9.1 (CRITICAL), with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H. The exploitability subscore is a maximum 3.9: network attack vector, low attack complexity, no privileges, no user interaction. Impact is high on confidentiality and availability; integrity is unaffected.
That combination, trivially reachable over HTTP with zero authentication, against a CRM platform holding customer and campaign data, makes internet-exposed Siebel Marketing deployments a high-priority target. As of 2026-08-18, CVE-2026-60754 does not appear in CISA's Known Exploited Vulnerabilities catalog, and no public reporting of in-the-wild exploitation has surfaced. Readers can confirm the current status directly against the KEV catalog, which is updated on a rolling basis; absence from it is not evidence that exploitation will not occur, particularly for a flaw this cheap to weaponize.
What's Vulnerable
- Vendor: Oracle Corporation
- Product: Oracle Siebel CRM, Siebel Apps - Marketing
- Component: Marketing
- Affected versions: 17.0 through 26.6 (inclusive)
The affected range spans nearly a decade of supported releases, so most production Siebel Marketing estates should be considered in scope until verified otherwise.
Patch Status
The fix is delivered through Oracle's Critical Patch Update program. Oracle issues Critical Patch Updates on a fixed quarterly schedule, January, April, July, and October, so administrators should consult the most recent CPU advisory covering Siebel CRM to confirm which patch level remediates this issue, apply the relevant patches for their Siebel version, and in the interim restrict HTTP access to Siebel Marketing endpoints from untrusted networks.
The NVD record was published 2026-08-18 with a status of "Received," meaning NVD enrichment and CPE mapping are still pending; the Oracle advisory is the authoritative source for patch identifiers and affected-version detail.
Sources
- Oracle Critical Patch Updates, Security Alerts and Bulletins; https://www.oracle.com/security-alerts/
- NVD, CVE-2026-60754, https://nvd.nist.gov/vuln/detail/CVE-2026-60754
- CISA Known Exploited Vulnerabilities Catalog; https://www.cisa.gov/known-exploited-vulnerabilities-catalog