Summary
CVE-2026-60796 is a high-severity vulnerability in the REST integration component of Oracle Siebel CRM. It allows an unauthenticated, network-based attacker to gain unauthorized access to sensitive data and cause a partial disruption of service. Oracle rates the flaw as "easily exploitable" and disclosed it in the August 2026 Critical Patch Update.
Technical details
- Root cause lies in the Siebel CRM Integration REST component, which improperly handles requests, allowing unauthorized data access.
- No authentication or user interaction is required to exploit the flaw.
- Attack vector is network-based over HTTP, targeting the exposed REST integration endpoints.
- Successful exploitation results in high-confidentiality impact (unauthorized access to sensitive data) and low-availability impact (partial service disruption); there is no integrity impact.
Affected software
- Oracle Siebel CRM Integration, versions 17.0 through 26.6
Severity
- CVSS v3.1 Base Score: 8.2 (High)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
Mitigation and recommended actions
- Immediate: Apply the Oracle Critical Patch Update for August 2026, which contains the fix for CVE-2026-60796 in affected Siebel CRM Integration versions (17.0–26.6).
- If immediate patching is not possible: Restrict network access to Siebel CRM REST integration endpoints (e.g., via firewall rules, VPN, or access control lists) to trusted hosts only, and monitor REST integration endpoint traffic for anomalous or unauthenticated access attempts until the patch can be applied.

