CVE-2026-60767
Analyzed Analyzed - Analysis Complete

Authentication Bypass in Siebel Apps Marketing

Vulnerability report for CVE-2026-60767, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-18

Last updated on: 2026-08-26

Assigner: Oracle

Description

Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this vulnerability can result in takeover of Siebel Apps - Marketing. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-18
Last Modified
2026-08-26
Generated
2026-09-08
AI Q&A
2026-08-19
EPSS Evaluated
2026-09-07
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
oracle siebel_apps_-_marketing From 17.0 (inc) to 26.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a vulnerability in Oracle Siebel CRM's Siebel Apps - Marketing product affecting versions 17.0 to 26.6. It allows a low-privileged attacker with network access via HTTP to take over the system. The vulnerability has a high CVSS score of 8.8 due to its impact on confidentiality, integrity, and availability.

Detection Guidance

This vulnerability affects Oracle Siebel CRM's Marketing component versions 17.0-26.6. Detection requires checking for vulnerable versions of the software. Use commands like 'grep' or package managers to verify installed versions. For example, check Siebel CRM version via application logs or database queries. No specific exploit commands are provided in the CVE details.

Impact Analysis

If exploited, an attacker could gain full control over the Siebel Apps - Marketing system. This could lead to unauthorized access to sensitive data, modification of critical information, or disruption of services, potentially causing significant operational and reputational damage.

Compliance Impact

This vulnerability could lead to breaches of GDPR or HIPAA by exposing personal or health data. Organizations using the affected Oracle Siebel CRM versions may face compliance violations, legal penalties, and loss of trust due to unauthorized data access or modification.

Mitigation Strategies

Apply the latest security patches from Oracle for Siebel Apps - Marketing versions 17.0-26.6. Restrict network access to the HTTP interface and limit privileges for users. Monitor for unusual activity and consider disabling the component if not in use.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-60767. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart