Sceawere
Vulnerability Detail
CVE-2026-70910UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Siebel CRM REST Confidentiality Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Siebel CRM Integration
- Attack Type
- Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-08-18T21:17:48.870Z",
"pubdate": "2026-08-18T21:17:48.870Z",
"executiveSummary": "An unauthenticated, network-accessible vulnerability exists within the REST component of the Oracle Siebel CRM Integration product, affecting supported versions 17.0 through 26.6. This security flaw enables remote attackers to compromise the Siebel CRM Integration subsystem without requiring prior authentication, user interaction, or specialized privileges.\nThe primary impact of this vulnerability is the unauthorized disclosure of critical data, leading to a complete compromise of confidentiality regarding all data accessible via the Siebel CRM Integration interface. With a CVSS 3.1 Base Score of 7.5 and a vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N, the vulnerability underscores significant risk to enterprise data assets due to its low attack complexity and lack of requisite privileges.\nExploitation requires network connectivity via the HTTP protocol directly to the vulnerable REST component. Successful exploitation allows threat actors to bypass authorization controls, harvesting sensitive business logic data and proprietary records exposed through the integration endpoints without leaving operational logs indicative of credential misuse.",
"technicalDetails": "The vulnerability resides within the REST component of the Oracle Siebel CRM Integration framework, specifically affecting software versions 17.0 to 26.6. The root cause stems from improper access control enforcement and inadequate input validation or session validation mechanisms within the HTTP-based REST API handlers.\nThe attack flow begins when an unauthenticated threat actor leverages network access over HTTP to transmit specially crafted requests directly to the vulnerable Siebel CRM Integration REST endpoints. Because the component fails to properly validate the caller's identity or enforce authorization policies prior to processing the request, the application treats the incoming request as valid.\nUpon receiving the malicious or unauthorized request, the vulnerable component processes the payload and queries the underlying database or data store. The application then retrieves the requested records and returns them in the HTTP response body to the unauthorized client. This bypasses all intended security boundaries designed to restrict data access to authenticated and authorized users only.\nThe exploitation method relies solely on network accessibility (AV:N) and low attack complexity (AC:L), requiring zero privileges (PR:N) and no user interaction (UI:N). The scope remains unchanged (S:U), but the confidentiality impact is absolute (C:H), resulting in unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data.\nPost-exploitation impact is strictly confined to the confidentiality vector, meaning integrity (I:N) and availability (A:N) are unaffected. However, the exposure of critical integration data can lead to secondary compromises, intellectual property theft, and regulatory non-compliance depending on the sensitivity of the data processed by the Siebel CRM Integration module."
}