CRITICAL 9.8 CVE-2026-61318 Published 18 Aug 2026

Oracle Siebel CRM Cloud Manager Unauthenticated Takeover Vulnerability

Worried this affects one of your servers?

A vulnerability has been found in the Siebel CRM Cloud Applications product of Oracle Siebel CRM, specifically in the Siebel Cloud Manager component. Supported versions 22.3 through 26.6 are affected.

The flaw is an easily exploitable takeover issue. An unauthenticated attacker with network access via HTTP can compromise Siebel CRM Cloud Applications, resulting in full takeover.

Impact details:

  • CVSS 3.1 Base Score: 9.8
  • Confidentiality, Integrity and Availability impacts: High
  • Attack vector: Network; Attack complexity: Low; No privileges required; No user interaction; Scope: Unchanged

Reference: CVE-2026-61318 on NVD

← Back to Security News