Oracle disclosed a critical, easily exploitable vulnerability in the Siebel Cloud Manager component of Siebel CRM Cloud Applications that lets a low-privileged network attacker fully take over the product and, according to Oracle, potentially reach beyond it into other systems.
What Is It
CVE-2026-61317 is a vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM, specifically the Siebel Cloud Manager component. Oracle rates it CVSS 3.1 base score 9.9 (CRITICAL) with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H (NVD).
The flaw is remotely reachable over HTTP, requires low attack complexity, needs only low privileges, and requires no user interaction. Successful exploitation results in complete takeover of Siebel CRM Cloud Applications.
Why It Matters
Three things push this to the top of the patch queue.
First, the scope is changed (S:C), Oracle explicitly notes that while the vulnerability lives in Siebel CRM Cloud Applications, attacks "may significantly impact additional products." By Oracle's own framing, the blast radius may not stop at the CRM boundary, though the advisory does not enumerate which downstream products are reachable.
Second, the barrier to entry is low. An attacker needs network access via HTTP and any low-privileged account; no admin credentials, no user tricked into clicking anything. Oracle's own wording is "easily exploitable."
Third, the impact is total across all three axes: high confidentiality, integrity, and availability loss, ending in product takeover. Siebel CRM deployments typically hold customer records, contracts, and sales pipeline data.
As of this writing, CVE-2026-61317 does not appear in the CISA Known Exploited Vulnerabilities catalog, so active exploitation is not confirmed at this time. That is not a reason to deprioritize a 9.9 with a public advisory attached.
What's Vulnerable
- Vendor: Oracle Corporation
- Product: Siebel CRM Cloud Applications (component: Siebel Cloud Manager)
- Affected versions: 22.3 through 26.6 inclusive
That is a wide supported-version band spanning several years of releases. Organizations running anything in the 22.3–26.6 range should assume they are affected until proven otherwise.
Patch Status
The supplied data does not identify which Oracle release vehicle carries the fix. Administrators should consult the Oracle security alerts page below for fixed versions and apply the relevant update to any Siebel CRM Cloud Applications instance in the 22.3–26.6 range. No specific remediation deadline is present in the supplied data.
The CVE record was published 2026-08-18 and remains in "Received" status at NVD, meaning NVD analysis is not yet complete and details may be revised.
Sources
- Oracle Security Alerts; Critical Patch Updates and Security Alerts: https://www.oracle.com/security-alerts/
- NVD, CVE-2026-61317: https://nvd.nist.gov/vuln/detail/CVE-2026-61317
- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog