CRITICAL
9.8 CVE-2026-61318 Published 18 Aug 2026
Oracle Siebel CRM Cloud Manager Unauthenticated Takeover Vulnerability
Worried this affects one of your servers?
A vulnerability has been found in the Siebel CRM Cloud Applications product of Oracle Siebel CRM, specifically in the Siebel Cloud Manager component. Supported versions 22.3 through 26.6 are affected.
The flaw is an easily exploitable takeover issue. An unauthenticated attacker with network access via HTTP can compromise Siebel CRM Cloud Applications, resulting in full takeover.
Impact details:
- CVSS 3.1 Base Score: 9.8
- Confidentiality, Integrity and Availability impacts: High
- Attack vector: Network; Attack complexity: Low; No privileges required; No user interaction; Scope: Unchanged
Reference: CVE-2026-61318 on NVD
← Back to Security News