Sceawere

Vulnerability Detail

CVE-2026-70859UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Siebel CRM Integration REST Takeover

Vulnerability Metadata

Severity
High
Score / CVSS
8.5
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Siebel CRM Integration
Attack Type
Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Integration. While the vulnerability is in Siebel CRM Integration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Siebel CRM Integration.
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Integration. While the vulnerability is in Siebel CRM Integration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Siebel CRM Integration. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.5",
  "pubDate": "2026-08-18T21:17:42.117Z",
  "pubdate": "2026-08-18T21:17:42.117Z",
  "executiveSummary": "A severe vulnerability affects the REST component of the Siebel CRM Integration product within Oracle Siebel CRM, impacting supported versions 17.0 through 26.6. This security flaw enables a low-privileged authenticated attacker with network access via HTTP to execute a full system compromise. The vulnerability is characterized by a scope change (S:C), indicating that successful exploitation of the Siebel CRM Integration component can propagate and significantly impact additional integrated products and underlying infrastructural systems.\nThe vulnerability yields a CVSS 3.1 Base Score of 8.5 with high impacts across Confidentiality, Integrity, and Availability (C:H/I:H/A:H). Exploitation requires network connectivity and low privileges, though the attack complexity is rated as high. Successful exploitation results in the complete takeover of the Siebel CRM Integration product, presenting substantial risk to enterprise data integrity and operational continuity. Remediation requires applying vendor-supplied patches or adhering to Oracle security advisories for the affected version range.",
  "technicalDetails": "The vulnerability resides within the REST integration component of Oracle Siebel CRM versions 17.0 to 26.6. The attack vector is network-based (AV:N), allowing remote threat actors to interact with the vulnerable REST endpoints over HTTP. Although the attack complexity is classified as high (AC:H) and requires low privileges (PR:L), no user interaction (UI:N) is necessary for successful exploitation.\nThe root cause stems from improper input validation, insecure deserialization, or flawed access control logic within the REST interface handling mechanism. A low-privileged user authenticated to the network can craft and transmit malicious HTTP payloads targeting the Siebel CRM Integration component. Due to insufficient bounds checking or improper handling of API requests within the REST subsystem, the crafted payload triggers unintended code execution or unauthorized administrative actions.\nThe attack flow proceeds as follows: First, the attacker establishes network connectivity to the exposed HTTP REST interface of the Siebel CRM Integration component. Second, utilizing low-privileged credentials, the attacker sends a specially crafted HTTP request containing the malicious payload designed to exploit the underlying flaw in the REST processing logic. Third, the component processes the payload insecurely, leading to memory corruption, arbitrary code execution, or privilege escalation within the context of the service.\nBecause of the scope change (S:C) characteristic, the compromise is not strictly contained within the boundaries of the Siebel CRM Integration product. Successful payload execution grants the attacker elevated privileges, leading to the complete takeover of the affected instance. Furthermore, lateral movement or exploitation of trust relationships allows the impact to extend to additional integrated products, compromising the broader enterprise architecture by granting unauthorized access to highly sensitive data streams, modifying core business logic, and causing denial of service conditions across dependent systems."
}
CVE-2026-70859: Siebel CRM Integration REST Takeover (HIGH Severity, CVSS: 8.5) - Sceawere