SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-62585 2026-08-18

CVE-2026-62585: Critical Unauthenticated Takeover in Oracle Siebel CRM Administration

"Oracle disclosed a CVSS 9.8 flaw in the Data Archival component of Siebel CRM Administration that lets an unauthenticated remote attacker fully compromise the product over HTTP."

Oracle disclosed a CVSS 9.8 flaw in the Data Archival component of Siebel CRM Administration that lets an unauthenticated remote attacker fully compromise the product over HTTP.

What Is It

CVE-2026-62585 is a critical vulnerability in the Siebel CRM Administration product of Oracle Siebel CRM, specifically in the Data Archival component. Oracle describes it as an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise Siebel CRM Administration. Successful attacks result in complete takeover of Siebel CRM Administration.

The CVSS 3.1 base score is 9.8 (CRITICAL), with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network attack vector, low attack complexity, no privileges required, no user interaction, and high impact to confidentiality, integrity, and availability. The record was published by Oracle's security alert channel on 2026-08-18 and currently carries NVD status "Received."

Why It Matters

Every barrier that normally slows an attacker is absent here: no credentials, no user interaction, and low complexity, reachable over standard HTTP. That combination puts internet-exposed or broadly reachable Siebel CRM Administration instances at immediate risk of full compromise, with all three impact metrics rated High.

CISA KEV does not list this CVE, so there is no confirmation of active exploitation at this time. That is not a reason to defer patching; the exploitability score of 3.9 is the maximum possible.

What's Vulnerable

No affected CPE entries were present in the NVD record at the time of publication.

Patch Status

The single reference supplied for this CVE is an Oracle security-alerts advisory URL, which points to the August 2026 advisory page. Organizations should consult that advisory to confirm which update covers their Siebel CRM Administration version and apply the corresponding patch. No specific remediation deadline or required-action directive was present in the supplied data, and no KEV due date applies since the CVE is not listed in the KEV catalog.

Sources