CVE-2026-60712 Overview
CVE-2026-60712 is an information disclosure vulnerability in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications. Oracle disclosed the flaw in the July 2026 Critical Patch Update. Supported versions 22.3 through 26.5 are affected.
The vulnerability allows a low-privileged attacker with local logon access to the infrastructure hosting Siebel CRM Cloud Applications to compromise confidentiality. Successful exploitation can result in unauthorized access to all data accessible by Siebel CRM Cloud Applications. The issue produces a scope change, meaning attacks may impact additional products beyond the vulnerable component.
Critical Impact
A local, authenticated attacker can read all data accessible to Siebel CRM Cloud Applications, with impact extending beyond the vulnerable component due to scope change.
Affected Products
- Oracle Siebel CRM Cloud Applications version 22.3 through 26.5
- Siebel Cloud Manager component
- Deployments where the attacker can obtain local logon to the hosting infrastructure
Discovery Timeline
- 2026-07-21 - CVE-2026-60712 published to NVD alongside the Oracle July 2026 Critical Patch Update
- 2026-07-21 - Last updated in NVD database
Technical Details for CVE-2026-60712
Vulnerability Analysis
The flaw resides in the Siebel Cloud Manager, a component responsible for orchestrating cloud-hosted Siebel CRM workloads. Oracle classifies the issue as easily exploitable and confidentiality-only. Integrity and availability are not affected.
The scope-change designation indicates that successful exploitation crosses a security authority boundary. An attacker operating within the Siebel Cloud Applications context can reach data managed under a different security scope, expanding the blast radius of a single compromised low-privileged account.
EPSS data reports an exploitation probability of 0.151% at the 4.765 percentile as of 2026-07-23. No public exploit code, CISA KEV entry, or in-the-wild activity has been reported.
Root Cause
Oracle has not published root-cause details. The CVSS metrics indicate the defect exposes sensitive data readable from an authenticated local context and permits a security-scope transition. Consult the Oracle Critical Patch Update - July 2026 advisory for vendor guidance.
Attack Vector
Exploitation requires local access to the infrastructure running Siebel CRM Cloud Applications and a valid low-privileged account. No user interaction is required. The attacker leverages the Siebel Cloud Manager component to retrieve data outside the intended authorization boundary of the compromised account.
No verified proof-of-concept code has been published. Refer to the Oracle advisory for technical remediation details.
Detection Methods for CVE-2026-60712
Indicators of Compromise
- Unexpected read operations against Siebel Cloud Manager configuration or metadata objects by low-privileged accounts
- Local logon sessions from service or shared accounts accessing Siebel Cloud Manager endpoints outside normal administrative windows
- Bulk queries or exports of Siebel CRM data initiated from infrastructure-adjacent shells rather than the Siebel application UI
Detection Strategies
- Enable Siebel audit trail logging for the Cloud Manager component and forward events to a centralized log platform
- Baseline normal per-user data access volumes in Siebel CRM and alert on statistical deviations
- Correlate operating-system logon events on Siebel hosts with subsequent Cloud Manager API activity to identify unusual chains
Monitoring Recommendations
- Monitor authentication events for low-privileged accounts logging into Siebel-hosting infrastructure
- Track access to sensitive Siebel business objects, especially cross-tenant or cross-scope reads
- Review privileged process execution on Siebel application servers for signs of local reconnaissance
How to Mitigate CVE-2026-60712
Immediate Actions Required
- Apply the fixes contained in the Oracle July 2026 Critical Patch Update to all Siebel CRM Cloud Applications instances running versions 22.3 through 26.5
- Inventory local accounts with logon rights to Siebel infrastructure and remove any that are unnecessary
- Rotate credentials for service and administrative accounts on Siebel hosts after patching
Patch Information
Oracle addressed CVE-2026-60712 in the July 2026 Critical Patch Update. Patch details and download links are available in the Oracle Critical Patch Update Advisory - July 2026. Apply patches per Oracle's guidance for your specific Siebel version.
Workarounds
- Restrict interactive and network logon to Siebel infrastructure hosts to a minimal set of administrative identities
- Enforce host-based access controls and jump-server requirements for any administrative access to Siebel Cloud Manager
- Isolate Siebel CRM Cloud Applications hosts on segmented networks with strict egress controls until patching completes
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

