Oracle disclosed CVE-2026-62588, a critical vulnerability in the Open Integration component of Oracle Siebel CRM Integration that lets a low-privileged remote attacker take over the product and potentially reach beyond it into adjacent systems.
What Is It
CVE-2026-62588 is a vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM, specifically the Open Integration component. Oracle describes it as easily exploitable: an attacker with network access over HTTP and only low privileges can compromise Siebel CRM Integration with no user interaction required. Successful exploitation can result in full takeover of Siebel CRM Integration.
The CVSS 3.1 base score is 9.9 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, network attack vector, low complexity, low privileges required, no user interaction, changed scope, and high impact to confidentiality, integrity, and availability. Per the NVD record, the entry was published by Oracle's security alert channel on 2026-08-18 and currently carries NVD status "Received."
Why It Matters
Two things drive the 9.9 score. First, the privilege bar is low, any authenticated foothold with minimal rights may be enough, which is a realistic position for an insider, a compromised service account, or a phished user. Second, the scope is changed: Oracle explicitly notes that attacks "may significantly impact additional products." A compromise may not stop at the integration layer. Siebel CRM Integration typically brokers data between CRM and downstream business systems, so a takeover could put that trust boundary, and the data crossing it; in the attacker's hands.
The CVE does not appear in the CISA KEV data reviewed for this brief, so there is no confirmed evidence of active exploitation at this time.
What's Vulnerable
- Vendor: Oracle Corporation
- Product: Oracle Siebel CRM, Siebel CRM Integration
- Component: Open Integration
- Affected versions: 25.12 through 26.6 (inclusive)
No CPE entries were present in the NVD record at time of writing.
Patch Status
Oracle publishes Critical Patch Updates on a fixed quarterly cadence, January, April, July, and October, per its Critical Patch Updates, Security Alerts and Bulletins index, which means an August release would fall outside the regular CPU schedule. An August disclosure date therefore suggests the fix was either delivered in the July 2026 Critical Patch Update or is being distributed through an out-of-cycle Security Alert. The advisory link carried in the CVE record is named as though it points to an August 2026 Critical Patch Update; we were not able to confirm what that URL resolves to, and it should be treated as unverified until checked directly.
Administrators running Siebel CRM Integration 25.12–26.6 should confirm the applicable patch level against Oracle's Critical Patch Updates, Security Alerts and Bulletins index or through My Oracle Support rather than relying on that link alone. No CISA-mandated remediation deadline applies, as the CVE is not present in the KEV data reviewed for this brief.
Sources
- Oracle advisory URL as referenced in the CVE record, unverified; not confirmed to correspond to a published Oracle advisory, https://www.oracle.com/security-alerts/cspuaug2026.html
- Oracle Critical Patch Updates, Security Alerts and Bulletins (quarterly CPU schedule), https://www.oracle.com/security-alerts/
- NVD, CVE-2026-62588, https://nvd.nist.gov/vuln/detail/CVE-2026-62588