SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-62512 2026-08-18

Oracle Siebel CRM Cloud Manager Flaw Scores 9.9 — Full Takeover From a Low-Privilege Account

"Oracle disclosed CVE-2026-62512, a critical (CVSS 9.9) vulnerability in the Siebel Cloud Manager component of Siebel CRM Cloud Applications that lets a low-privileged attacker with network access take over the product…"

Oracle disclosed CVE-2026-62512, a critical (CVSS 9.9) vulnerability in the Siebel Cloud Manager component of Siebel CRM Cloud Applications that lets a low-privileged attacker with network access take over the product and reach beyond it.

What Is It

CVE-2026-62512 is a vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM, specifically the Siebel Cloud Manager component. Oracle describes it as easily exploitable: an attacker with low privileges and network access over HTTP can compromise Siebel CRM Cloud Applications. Successful exploitation results in full takeover of the affected product.

The CVSS 3.1 vector is AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, base score 9.9, rated CRITICAL, with an exploitability subscore of 3.1 and impact subscore of 6.0. The record was published by Oracle's security alert contact on 2026-08-18 and currently carries NVD status "Received."

Why It Matters

Three things stack badly here. Attack complexity is low and no user interaction is required, so there's no meaningful barrier once an attacker holds any low-privilege account. The scope is changed (S:C), Oracle explicitly notes that while the vulnerability lives in Siebel CRM Cloud Applications, attacks "may significantly impact additional products." And the outcome is total: high confidentiality, integrity, and availability impact, described by Oracle as takeover.

Siebel CRM holds customer records, sales pipeline, and service data. A takeover of the cloud management layer is a takeover of that data; plus whatever the scope change reaches next.

No CISA KEV entry was supplied for this CVE, so there is no confirmation of active exploitation at this time.

What's Vulnerable

That is a wide window; roughly four years of supported releases.

Patch Status

Oracle addressed this in the August 2026 Critical Patch Update / security alert. Administrators running Siebel CRM Cloud Applications 22.3–26.6 should consult Oracle's advisory and apply the corresponding fix. No specific CISA-mandated remediation deadline was supplied in the source material.

Sources