Summary
CVE-2026-62589 is a vulnerability in the Open Integration component of Oracle Siebel CRM’s Siebel CRM Integration product that allows an unauthenticated, network-based attacker to compromise the system over HTTP. Successful exploitation can result in unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to all data accessible to Siebel CRM Integration. Oracle rates the flaw HIGH severity (CVSS 3.1 base score 8.7).
Technical details
- Root cause: a flaw in the Open Integration component of Siebel CRM Integration that fails to properly enforce access controls on integration requests.
- Trigger conditions: Oracle describes the vulnerability as "difficult to exploit," but no authentication or user interaction is required to trigger it.
- Attack vector: network access via HTTP; the attack requires no privileges (PR:N) and no user interaction (UI:N).
- Scope: the CVSS vector includes Scope Changed (S:C), meaning a successful attack can impact components beyond the vulnerable one.
- Impact: unauthorized creation, deletion, or modification of critical/all accessible data (Integrity: High) and unauthorized read access to critical/all accessible data (Confidentiality: High); no impact to availability (A:N).
Affected software
- Oracle Siebel CRM Integration (Siebel CRM), component: Open Integration — versions 25.12 through 26.6 (inclusive).
Severity
- CVSS v3.1 Base Score: 8.7 (High)
- Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Mitigation and recommended actions
- Immediate: Apply the fix provided by Oracle in the August 2026 Critical Patch Update / Security Alert (cspuaug2026) to bring Siebel CRM Integration deployments to a non-vulnerable version.
- If patching cannot be applied immediately: restrict network access to Siebel CRM Integration’s Open Integration HTTP endpoints to trusted networks only, and monitor for anomalous integration requests until the patch can be applied. Oracle strongly recommends applying the fix as soon as possible; there is no substitute mitigation documented by the vendor.

