Junglewise Threat Intelligence

CVE-2026-46885: Oracle Siebel CRM privilege escalation in EAI component

CVE-2026-46885 · Severity: high · CVSS 8.8 · Published 2026-06-17

Vendors: Oracle, Oracle Corporation.

Executive brief

A vulnerability in the Enterprise Application Integration (EAI) component of Oracle Siebel CRM allows an attacker with low-level user credentials to gain full control over the integration system. This component is responsible for connecting Siebel CRM with other business applications and data sources. A successful exploit could lead to a total compromise of the integration platform, potentially exposing sensitive customer data or disrupting critical business workflows.

Technical details

This vulnerability is classified as Improper Privilege Management (CWE-269) within the Enterprise Application Integration (EAI) component of Oracle Siebel CRM. It is easily exploitable by a low-privileged attacker with network access via HTTP. The flaw allows an authenticated user to bypass intended security restrictions and compromise the Siebel CRM Integration environment. Successful exploitation results in a total loss of confidentiality, integrity, and availability (takeover of the component). Affected versions include 17.0 through 26.5. Users are advised to refer to the Oracle Critical Patch Update for remediation steps.

Affected products

  • Oracle Corporation Siebel CRM Integration (EAI) 17.0 through 26.5

Timeline

  • 2026-06-17: disclosed: Initial publication by Oracle and NVD.

References