Junglewise Threat Intelligence

CVE-2026-46886: Oracle Siebel CRM improper access control in Siebel Apps - Marketing

CVE-2026-46886 · Severity: high · CVSS 8.8 · Published 2026-06-17

Technologies: Oracle Siebel Apps - Marketing. Vendors: Oracle.

Executive brief

A security vulnerability exists in the Marketing component of Oracle Siebel CRM, a platform used by large organizations to manage customer relationships and marketing campaigns. An attacker with basic user access can exploit this flaw over the network to gain full control of the Marketing application. This could lead to the theft of sensitive customer data, unauthorized changes to marketing operations, or a total shutdown of the service.

Technical details

A vulnerability in the Marketing component of Oracle Siebel CRM (specifically Siebel Apps - Marketing) is classified as Improper Access Control (CWE-284). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows the attacker to bypass security restrictions and achieve a complete takeover of the affected component, impacting confidentiality, integrity, and availability. Affected versions range from 17.0 through 26.5. Users are advised to refer to the Oracle Critical Patch Update for remediation steps.

Affected products

  • Oracle Siebel Apps - Marketing 17.0-26.5

Timeline

  • 2026-06-17: disclosed: Initial disclosure by Oracle
  • 2026-06-17: advisory: NVD publication date

References

Related threats