Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-60797

CVE-2026-60797: Siebel CRM Auth Bypass Vulnerability

CVE-2026-60797 is an authentication bypass vulnerability in Oracle Siebel CRM Integration that allows unauthorized data access and modification. This article covers technical details, affected versions, impact, and mitigation.

Published:

CVE-2026-60797 Overview

CVE-2026-60797 is an access control vulnerability [CWE-284] in the Siebel CRM Integration product of Oracle Siebel CRM. The flaw resides in the REST component and affects supported versions 17.0 through 26.6. An unauthenticated attacker with network access via HTTPS can exploit the weakness to compromise Siebel CRM Integration. Successful exploitation grants unauthorized read, create, delete, or modify access to critical data or all data accessible through Siebel CRM Integration. Oracle rates the flaw as difficult to exploit, reflected in the CVSS attack complexity rating.

Critical Impact

Remote unauthenticated attackers can gain full read and write access to data exposed through the Siebel CRM Integration REST interface.

Affected Products

  • Oracle Siebel CRM Integration versions 17.0 through 26.6
  • Siebel CRM REST component
  • Oracle Siebel CRM deployments exposing the Integration REST interface over HTTPS

Discovery Timeline

  • 2026-08-18 - CVE-2026-60797 published to NVD
  • 2026-08-20 - Last updated in NVD database

Technical Details for CVE-2026-60797

Vulnerability Analysis

The vulnerability affects the REST component of Siebel CRM Integration, a module that exposes REST endpoints for external systems to exchange data with the Siebel platform. An attacker sends crafted HTTPS requests to the REST interface without providing valid credentials. The issue is classified under [CWE-284] Improper Access Control, indicating the component fails to correctly enforce authorization checks on privileged operations. Exploitation results in unauthorized creation, deletion, or modification of records, along with unauthorized read access to all data reachable through the Integration REST surface. Availability of the target system is not affected, per Oracle's CVSS assessment.

Root Cause

The root cause is improper access control on the Siebel CRM Integration REST endpoints. Authorization logic does not correctly restrict unauthenticated requests from performing operations that should require valid identity and privileges. Oracle has not published low-level technical details in the public advisory.

Attack Vector

The attack is remote and network-based over HTTPS. No prior authentication is required, and no user interaction is needed. Oracle characterizes exploitation as difficult, which typically indicates that specific timing, configuration, or request conditions must be met to trigger the flaw. The Exploit Prediction Scoring System (EPSS) reports a probability of 0.301% with a percentile of 22.832 as of 2026-08-20.

No verified proof-of-concept code is publicly available. Refer to the Oracle Security Alert for vendor-supplied technical details.

Detection Methods for CVE-2026-60797

Indicators of Compromise

  • Unauthenticated HTTPS requests to Siebel CRM Integration REST endpoints originating from external or unexpected source addresses.
  • Unexpected record creation, modification, or deletion events in Siebel audit logs without corresponding authenticated user sessions.
  • Anomalous spikes in REST API traffic volume or error rates against the Integration component.

Detection Strategies

  • Enable and review Siebel audit trails for data changes that cannot be attributed to authenticated business users or approved integration accounts.
  • Inspect HTTPS access logs on web tier components fronting Siebel for REST calls that bypass expected authentication headers.
  • Correlate application-layer telemetry with network flow data to identify unauthorized clients interacting with the Integration REST surface.

Monitoring Recommendations

  • Forward Siebel application, web server, and reverse proxy logs to a centralized analytics platform for continuous review.
  • Alert on REST request patterns targeting Integration endpoints from unapproved IP ranges or user agents.
  • Baseline normal Integration REST traffic and generate alerts on statistically significant deviations in method, path, or payload characteristics.

How to Mitigate CVE-2026-60797

Immediate Actions Required

  • Apply the security fix referenced in the Oracle Critical Patch Update advisory for August 2026 to all affected Siebel CRM Integration deployments.
  • Inventory all Siebel CRM Integration instances running versions 17.0 through 26.6 and prioritize internet-exposed systems.
  • Restrict network access to the Siebel Integration REST endpoints to trusted source networks pending patch deployment.

Patch Information

Oracle addressed CVE-2026-60797 as part of a Critical Patch Update. Consult the Oracle Security Alert for the specific patch identifiers, downloads, and installation guidance corresponding to your Siebel CRM version.

Workarounds

  • Place the Siebel CRM Integration REST interface behind a web application firewall configured to enforce authentication on all requests.
  • Use network segmentation and allow-lists to permit REST access only from vetted integration partners.
  • Disable or block the Integration REST component if it is not required for business operations until patching completes.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.