Sceawere
Vulnerability Detail
CVE-2026-70949UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Siebel CRM Deployment Takeover
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Siebel CRM Deployment
- Attack Type
- Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-08-18T21:17:53.153Z",
"pubdate": "2026-08-18T21:17:53.153Z",
"executiveSummary": "An easily exploitable vulnerability exists within the Server Infrastructure component of the Oracle Siebel CRM Deployment product, affecting supported versions 17.0 through 26.6. This security flaw allows a low-privileged remote attacker with network access via the HTTP protocol to execute unauthorized operations against the targeted infrastructure.\nSuccessful exploitation of this vulnerability leads to a complete system takeover of the Siebel CRM Deployment, granting the adversary full control over the affected application environment. The severity of this issue is reflected by a CVSS 3.1 Base Score of 8.8, with high impact ratings across confidentiality, integrity, and availability metrics.\nThe attack vector is network-based (AV:N), requiring low network complexity (AC:L) and low privileges (PR:L), while requiring no user interaction (UI:N) and maintaining a scope of unchanged (S:U). The risk implications are severe, as unauthorized actors can compromise sensitive data, alter application logic, and disrupt core business operations managed by the CRM system.",
"technicalDetails": "The vulnerability resides in the Server Infrastructure component of Oracle Siebel CRM Deployment, specifically within versions 17.0-26.6. The root cause stems from insufficient validation and processing of HTTP-based inputs handled by the vulnerable infrastructure, allowing authenticated low-privileged users to manipulate execution flows or internal states.\nExploitation requires the attacker to possess network connectivity to the vulnerable endpoint exposed via HTTP. Because the vulnerability requires low privileges (PR:L), the attacker must authenticate with minimal credentials before initiating the exploit payload. No user interaction (UI:N) is required, making automated or direct programmatic exploitation feasible.\nThe attack flow proceeds as follows: First, the adversary establishes an HTTP connection to the exposed Oracle Siebel CRM Deployment interface. Second, the attacker authenticates using low-privileged credentials to interact with the Server Infrastructure component. Third, the attacker transmits a specially crafted HTTP request designed to exploit the input handling or logic flaw within the server components. Fourth, the application processes the malicious payload without adequate bounds checking or authorization verification, leading to arbitrary execution or state manipulation.\nPost-exploitation impact encompasses the total takeover of the Siebel CRM Deployment. An attacker achieving this level of compromise can manipulate database records, exfiltrate confidential enterprise data, modify system configurations, inject malicious code into the application infrastructure, and cause denial-of-service conditions across the availability domain."
}