Summary
CVE-2026-62585 is a critical, unauthenticated vulnerability in the Data Archival component of Oracle Siebel CRM Administration. It allows a remote attacker with only network access via HTTP — no credentials or user interaction required — to completely compromise the affected system. Oracle rates this issue 9.8 (Critical) and disclosed it as part of the August 2026 Critical Security Patch Update.
Technical details
- Root cause lies in the Data Archival component of Siebel CRM Administration.
- The flaw is remotely exploitable over HTTP without any authentication.
- Attack complexity is low, requiring no special conditions, privileges, or user interaction.
- Successful exploitation can result in complete takeover of Siebel CRM Administration, impacting confidentiality, integrity, and availability.
Affected software
- Oracle Siebel CRM Administration versions 25.12 through 26.6
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the patch provided in Oracle’s August 2026 Critical Security Patch Update for Siebel CRM Administration.
- If immediate patching is not possible: Restrict network access to Siebel CRM Administration interfaces (e.g., via firewall rules or VPN-only access) to trusted management networks until the patch can be applied, and monitor for unusual administration/archival activity.

