Junglewise Threat Intelligence

CVE-2026-46884: Oracle Siebel CRM improper access control in Marketing component

CVE-2026-46884 · Severity: critical · CVSS 9.8 · Published 2026-06-17

Technologies: Oracle Siebel Apps - Marketing. Vendors: Oracle, Oracle Corporation.

Executive brief

A critical vulnerability has been identified in Oracle Siebel CRM's Marketing component, which is used by organizations to manage large-scale marketing campaigns and customer data. An unauthorized person can remotely take full control of the application over the internet without needing any login credentials. This could lead to a total loss of sensitive customer information, unauthorized modification of marketing data, and complete disruption of marketing operations.

Technical details

This vulnerability (CVE-2026-46884) is classified as an improper access control issue (CWE-284) within the Marketing component of Oracle Siebel CRM. It is highly exploitable as it requires no authentication (PR:N) and no user interaction (UI:N). An attacker can exploit this flaw over the network via HTTP to gain full control over the affected Siebel Apps - Marketing instance. Successful exploitation results in a total compromise of confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update for June 2026 for remediation steps.

Affected products

  • Oracle Corporation Siebel Apps - Marketing 17.0-26.5

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle June 2026 Critical Patch Update released

References

Related threats