{"cve":"CVE-2026-62588","enrichment":{"affected":[{"configurations":[{"platform":null,"status":"affected","versions":{"scheme":"generic","value":"[25.12,26.6]"}}],"enrichment":{"confidence":95.0,"confidence_source":"inferred","scores":[{"score":95.0,"source":"inferred"},{"score":100.0,"source":"matching"}]},"original":{"product":"Siebel CRM Integration","source":"cna","vendor":"Oracle Corporation"},"product":"siebel_crm_integration","vendor":"oracle"}],"created":"2026-08-19T01:00:04.225024+00:00","title":"Remote Attack Enables Full Takeover of Oracle Siebel CRM Integration","updated":"2026-08-21T11:30:04.189950+00:00","vendors":["oracle","oracle$PRODUCT$siebel_crm_integration"]},"epss":{"score":0.00432},"mitre":{"cpes":["cpe:2.3:a:oracle:siebel_crm_integration:*:*:*:*:*:*:*:*"],"created":"2026-08-18T21:00:37.801000+00:00","description":"Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration).  Supported versions that are affected are 25.12-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Integration.  While the vulnerability is in Siebel CRM Integration, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Siebel CRM Integration. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":9.9,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"},"cvssV4_0":{}},"mitre_repo_path":"cves/2026/62xxx/CVE-2026-62588.json","references":["https://www.oracle.com/security-alerts/cspuaug2026.html"],"title":null,"updated":"2026-08-20T03:56:24.332000+00:00","vendors":["oracle","oracle$PRODUCT$siebel_crm_integration"],"weaknesses":[]},"nvd":{"cpes":["cpe:2.3:a:oracle:siebel_crm:*:*:*:*:*:*:*:*"],"created":"2026-08-18T21:17:11.003000+00:00","description":"Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration).  Supported versions that are affected are 25.12-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Integration.  While the vulnerability is in Siebel CRM Integration, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Siebel CRM Integration. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":9.9,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"},"cvssV4_0":{}},"nvd_repo_path":"2026/CVE-2026-62588.json","references":["https://www.oracle.com/security-alerts/cspuaug2026.html"],"title":null,"updated":"2026-08-20T15:10:34.050000+00:00","vendors":["oracle","oracle$PRODUCT$siebel_crm"],"weaknesses":["CWE-284"]},"opencve":{"changes":[{"created":"2026-08-18T21:15:00+00:00","data":[{"details":{"new":"Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration).  Supported versions that are affected are 25.12-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Integration.  While the vulnerability is in Siebel CRM Integration, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Siebel CRM Integration. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).","old":null},"type":"description"},{"details":["oracle","oracle$PRODUCT$siebel_crm_integration"],"type":"first_time"},{"details":{"added":["cpe:2.3:a:oracle:siebel_crm_integration:*:*:*:*:*:*:*:*"],"removed":[]},"type":"cpes"},{"details":{"added":["oracle","oracle$PRODUCT$siebel_crm_integration"],"removed":[]},"type":"vendors"},{"details":{"added":["https://www.oracle.com/security-alerts/cspuaug2026.html"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV3_1":{"score":9.9,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"de6cf9e3-30d0-4153-99a2-6a66c9d76b39"},{"created":"2026-08-19T01:15:00+00:00","data":[{"details":{"new":"Remote Code Execution in Oracle Siebel CRM Integration via Unauthenticated HTTP Access","old":null},"type":"title"},{"details":{"added":["CWE-284","CWE-287"],"removed":[]},"type":"weaknesses"}],"id":"be2f17db-44e1-46b2-b302-d28d57e07463"},{"created":"2026-08-20T05:30:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"6fe5e02a-393b-4af1-9a86-9ada4edb6f5d"},{"created":"2026-08-20T15:30:00+00:00","data":[{"details":["oracle$PRODUCT$siebel_crm"],"type":"first_time"},{"details":{"added":["cpe:2.3:a:oracle:siebel_crm:*:*:*:*:*:*:*:*"],"removed":[]},"type":"cpes"},{"details":{"added":["oracle$PRODUCT$siebel_crm"],"removed":[]},"type":"vendors"}],"id":"a9a6495c-8729-4a6b-9142-3b690c046248"},{"created":"2026-08-21T09:30:00+00:00","data":[{"details":{"new":null,"old":"Remote Code Execution in Oracle Siebel CRM Integration via Unauthenticated HTTP Access"},"type":"title"},{"details":{"added":[],"removed":["CWE-287"]},"type":"weaknesses"}],"id":"dfe792d0-ba24-4fdf-b176-a9620d79de9d"},{"created":"2026-08-21T11:45:00+00:00","data":[{"details":{"new":"Remote Attack Enables Full Takeover of Oracle Siebel CRM Integration","old":null},"type":"title"}],"id":"861ed5e6-3c44-44e9-85a2-bd7efc11323b"}],"cpes":{"data":["cpe:2.3:a:oracle:siebel_crm:*:*:*:*:*:*:*:*","cpe:2.3:a:oracle:siebel_crm_integration:*:*:*:*:*:*:*:*"],"providers":["mitre","nvd"]},"created":{"data":"2026-08-18T21:00:37.801000+00:00","provider":"mitre"},"description":{"data":"Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration).  Supported versions that are affected are 25.12-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Integration.  While the vulnerability is in Siebel CRM Integration, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Siebel CRM Integration. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":9.9,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"},"provider":"mitre"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.00432},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://www.oracle.com/security-alerts/cspuaug2026.html"],"providers":["mitre","nvd"]},"title":{"data":"Remote Attack Enables Full Takeover of Oracle Siebel CRM Integration","provider":"enrichment"},"updated":{"data":"2026-08-21T11:30:04.189950+00:00","provider":"enrichment"},"vendors":{"data":["oracle","oracle$PRODUCT$siebel_crm","oracle$PRODUCT$siebel_crm_integration"],"providers":["mitre","nvd","enrichment"]},"weaknesses":{"data":["CWE-284"],"providers":["nvd","vulnrichment"]}},"vulnrichment":{"cpes":[],"created":"2026-08-18T21:00:37.801000+00:00","description":"Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration).  Supported versions that are affected are 25.12-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Integration.  While the vulnerability is in Siebel CRM Integration, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Siebel CRM Integration. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"references":[],"title":null,"updated":"2026-08-19T17:32:42.515000+00:00","vendors":[],"vulnrichment_repo_path":"2026/62xxx/CVE-2026-62588.json","weaknesses":["CWE-284"]}}