Sceawere
Vulnerability Detail
CVE-2026-70856UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Siebel CRM Deployment Takeover Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Siebel CRM Deployment
- Attack Type
- Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment.
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Migration). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-08-18T21:17:41.737Z",
"pubdate": "2026-08-18T21:17:41.737Z",
"executiveSummary": "An unauthenticated, network-accessible vulnerability exists within the Migration component of the Oracle Siebel CRM Deployment product, specifically affecting supported versions 17.0 through 26.6. This security flaw enables a remote attacker to achieve a complete system takeover of the targeted Siebel CRM Deployment instance over the HTTP protocol.\nAlthough the vulnerability is classified as difficult to exploit due to its high attack complexity and the requirement for human interaction from a third party, successful exploitation yields severe consequences. The impact encompasses complete compromise of confidentiality, integrity, and availability, translating to full administrative control over the affected deployment.\nThe risk profile is elevated due to the requirement of only network access and zero prior authentication privileges, although the attack vector strictly depends on social engineering or user-assisted interaction to successfully execute the payload. Organizations utilizing vulnerable versions of Oracle Siebel CRM must prioritize remediation efforts to prevent unauthorized remote takeover scenarios.",
"technicalDetails": "The vulnerability resides in the Migration component of the Oracle Siebel CRM Deployment product, impacting software versions 17.0 through 26.6. The architectural flaw exposes internal deployment mechanisms over standard HTTP network services, permitting unauthenticated remote interactions with sensitive administrative functionality.\nExploitation of this flaw requires an unauthenticated attacker to interact with the target system via the network over HTTP. Despite the absence of authentication and privilege prerequisites, the attack vector possesses a high attack complexity rating and mandates explicit human interaction from a user other than the attacker, such as a targeted administrator or operator interacting with a malicious link or crafted interface.\nThe attack flow commences when the attacker crafts a malicious HTTP request or payload targeted at the vulnerable Migration component. Because the vulnerability requires human interaction, the attacker typically leverages social engineering techniques to induce a victim to perform an action within the application context. Upon execution, the payload bypasses existing security boundaries due to insufficient validation or improper handling of incoming requests within the Migration module.\nFollowing successful exploitation, the payload behavior culminates in unauthorized command execution or administrative session hijacking within the Siebel CRM Deployment environment. The post-exploitation impact is critical, resulting in a full system takeover. This grants the adversary complete operational control over the affected infrastructure, allowing arbitrary modification or extraction of confidential data, alteration of system integrity, and total disruption of service availability, perfectly aligning with the maximum CVSS 3.1 base score metrics for confidentiality, integrity, and availability impacts."
}