cve-2026-61339
HIGH CVSS 7.3 opencveVulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications. While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data as well as unauthorized update, insert or delete access to some of Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 7.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
- Published
- 2026-08-18 21:17 UTC
- Last Modified
- 2026-09-01
CVSS details not available.
No product information available.
| Version | Base | Severity | Vector | Exploitability | Impact | Source |
|---|---|---|---|---|---|---|
| 3.1 | 7.3 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N |
mitre | ||
| 3.1 | 7.3 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N |
nvd | ||
| 3.1 | 7.3 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N |
opencve |
No references available.
{
"cve": "CVE-2026-61339",
"enrichment": {
"affected": [
{
"configurations": [
{
"platform": null,
"status": "affected",
"versions": {
"scheme": "generic",
"value": "[22.3,26.6]"
}
}
],
"enrichment": {
"confidence": 95.0,
"confidence_source": "inferred",
"scores": [
{
"score": 95.0,
"source": "inferred"
},
{
"score": 100.0,
"source": "matching"
}
]
},
"original": {
"product": "Siebel CRM Cloud Applications",
"source": "cna",
"vendor": "Oracle Corporation"
},
"product": "siebel_crm_cloud_applications",
"vendor": "oracle"
}
],
"created": "2026-08-19T00:45:03.871116+00:00",
"title": "Low-Privilege Access Allows Unauthorized Data Read and Modification in Oracle Siebel CRM Cloud Applications",
"updated": "2026-08-21T13:15:05.446574+00:00",
"vendors": [
"oracle",
"oracle$PRODUCT$siebel_crm_cloud_applications"
]
},
"epss": {
"score": 0.00151
},
"mitre": {
"cpes": [
"cpe:2.3:a:oracle:siebel_crm_cloud_applications:*:*:*:*:*:*:*:*"
],
"created": "2026-08-18T21:00:09.254000+00:00",
"description": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications. While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data as well as unauthorized update, insert or delete access to some of Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 7.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 7.3,
"vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
},
"cvssV4_0": {}
},
"mitre_repo_path": "cves/2026/61xxx/CVE-2026-61339.json",
"references": [
"https://www.oracle.com/security-alerts/cspuaug2026.html"
],
"title": null,
"updated": "2026-08-21T03:56:11.122000+00:00",
"vendors": [
"oracle",
"oracle$PRODUCT$siebel_crm_cloud_applications"
],
"weaknesses": []
},
"nvd": {
"cpes": [
"cpe:2.3:a:oracle:siebel_crm:*:*:*:*:*:*:*:*"
],
"created": "2026-08-18T21:17:00.673000+00:00",
"description": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications. While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data as well as unauthorized update, insert or delete access to some of Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 7.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 7.3,
"vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
},
"cvssV4_0": {}
},
"nvd_repo_path": "2026/CVE-2026-61339.json",
"references": [
"https://www.oracle.com/security-alerts/cspuaug2026.html"
],
"title": null,
"updated": "2026-09-01T19:55:44.673000+00:00",
"vendors": [
"oracle",
"oracle$PRODUCT$siebel_crm"
],
"weaknesses": [
"CWE-284"
]
},
"opencve": {
"changes": [
{
"created": "2026-08-18T21:15:00+00:00",
"data": [
{
"details": {
"new": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications. While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data as well as unauthorized update, insert or delete access to some of Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 7.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
"old": null
},
"type": "description"
},
{
"details": [
"oracle",
"oracle$PRODUCT$siebel_crm_cloud_applications"
],
"type": "first_time"
},
{
"details": {
"added": [
"cpe:2.3:a:oracle:siebel_crm_cloud_applications:*:*:*:*:*:*:*:*"
],
"removed": []
},
"type": "cpes"
},
{
"details": {
"added": [
"oracle",
"oracle$PRODUCT$siebel_crm_cloud_applications"
],
"removed": []
},
"type": "vendors"
},
{
"details": {
"added": [
"https://www.oracle.com/security-alerts/cspuaug2026.html"
],
"removed": []
},
"type": "references"
},
{
"details": {
"added": {
"cvssV3_1": {
"score": 7.3,
"vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "ce6cc26d-049e-4814-9159-26faeb828447"
},
{
"created": "2026-08-19T01:00:00+00:00",
"data": [
{
"details": {
"new": "Low‑Privilege Logon Exploitation Allowing Unauthorized Data Access in Siebel CRM Cloud Applications",
"old": null
},
"type": "title"
},
{
"details": {
"added": [
"CWE-284",
"CWE-285"
],
"removed": []
},
"type": "weaknesses"
}
],
"id": "6fdc585f-48c8-4922-8d49-c0c8eb043701"
},
{
"created": "2026-08-21T05:30:00+00:00",
"data": [
{
"details": {
"added": {
"ssvc": {
"options": {
"Automatable": "no",
"Exploitation": "none",
"Technical Impact": "total"
},
"version": "2.0.3"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "d107e8ad-44e9-4aef-a028-b0e74a28bf41"
},
{
"created": "2026-08-21T11:45:00+00:00",
"data": [
{
"details": {
"new": null,
"old": "Low‑Privilege Logon Exploitation Allowing Unauthorized Data Access in Siebel CRM Cloud Applications"
},
"type": "title"
},
{
"details": {
"added": [],
"removed": [
"CWE-285"
]
},
"type": "weaknesses"
}
],
"id": "77112dd8-1d61-4344-8582-ad0a4b357e5e"
},
{
"created": "2026-08-21T13:30:00+00:00",
"data": [
{
"details": {
"new": "Low-Privilege Access Allows Unauthorized Data Read and Modification in Oracle Siebel CRM Cloud Applications",
"old": null
},
"type": "title"
}
],
"id": "8ac54f85-8b15-42d3-afa4-5c55925424e5"
},
{
"created": "2026-09-01T22:00:00+00:00",
"data": [
{
"details": [
"oracle$PRODUCT$siebel_crm"
],
"type": "first_time"
},
{
"details": {
"added": [
"cpe:2.3:a:oracle:siebel_crm:*:*:*:*:*:*:*:*"
],
"removed": []
},
"type": "cpes"
},
{
"details": {
"added": [
"oracle$PRODUCT$siebel_crm"
],
"removed": []
},
"type": "vendors"
}
],
"id": "45551c58-9dba-45fb-b576-7562e171ba0c"
}
],
"cpes": {
"data": [
"cpe:2.3:a:oracle:siebel_crm:*:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:siebel_crm_cloud_applications:*:*:*:*:*:*:*:*"
],
"providers": [
"mitre",
"nvd"
]
},
"created": {
"data": "2026-08-18T21:00:09.254000+00:00",
"provider": "mitre"
},
"description": {
"data": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications. While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data as well as unauthorized update, insert or delete access to some of Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 7.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
"provider": "mitre"
},
"metrics": {
"cvssV2_0": {
"data": {},
"provider": null
},
"cvssV3_0": {
"data": {},
"provider": null
},
"cvssV3_1": {
"data": {
"score": 7.3,
"vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
},
"provider": "mitre"
},
"cvssV4_0": {
"data": {},
"provider": null
},
"epss": {
"data": {
"score": 0.00151
},
"provider": "first"
},
"kev": {
"data": {},
"provider": null
},
"ssvc": {
"data": {
"options": {
"Automatable": "no",
"Exploitation": "none",
"Technical Impact": "total"
},
"version": "2.0.3"
},
"provider": "vulnrichment"
},
"threat_severity": {
"data": null,
"provider": null
}
},
"references": {
"data": [
"https://www.oracle.com/security-alerts/cspuaug2026.html"
],
"providers": [
"mitre",
"nvd"
]
},
"title": {
"data": "Low-Privilege Access Allows Unauthorized Data Read and Modification in Oracle Siebel CRM Cloud Applications",
"provider": "enrichment"
},
"updated": {
"data": "2026-09-01T19:55:44.673000+00:00",
"provider": "nvd"
},
"vendors": {
"data": [
"oracle",
"oracle$PRODUCT$siebel_crm",
"oracle$PRODUCT$siebel_crm_cloud_applications"
],
"providers": [
"mitre",
"nvd",
"enrichment"
]
},
"weaknesses": {
"data": [
"CWE-284"
],
"providers": [
"nvd",
"vulnrichment"
]
}
},
"vulnrichment": {
"cpes": [],
"created": "2026-08-18T21:00:09.254000+00:00",
"description": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications. While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data as well as unauthorized update, insert or delete access to some of Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 7.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {},
"cvssV4_0": {},
"kev": {},
"ssvc": {
"options": {
"Automatable": "no",
"Exploitation": "none",
"Technical Impact": "total"
},
"version": "2.0.3"
}
},
"references": [],
"title": null,
"updated": "2026-08-20T16:46:32.258000+00:00",
"vendors": [],
"vulnrichment_repo_path": "2026/61xxx/CVE-2026-61339.json",
"weaknesses": [
"CWE-284"
]
}
}