CVE-2026-60765
EUVD-2026-6142518.08.2026, 21:16
Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this vulnerability can result in takeover of Siebel Apps - Marketing. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| oracle | siebel_apps_-_marketing | 17.0 ≤ 𝑥 ≤ 26.6 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-346 - Origin Validation ErrorThe software does not properly verify that the source of data or communication is valid.
- CWE-306 - Missing Authentication for Critical FunctionThe product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.