Executive brief
A critical vulnerability has been identified in Oracle Siebel CRM's Marketing component, which is used by businesses to manage large-scale marketing campaigns and customer data. An unauthorized person can exploit this flaw over the internet to gain full control of the application without needing a username or password. This could lead to a total loss of customer data confidentiality, unauthorized changes to marketing operations, and a complete shutdown of the service.
Technical details
A vulnerability in the Marketing component of Oracle Siebel CRM (versions 17.0 through 26.5) allows for a complete system takeover. The flaw is categorized as easily exploitable and can be triggered by an unauthenticated attacker with network access via HTTP. While the specific CWE is not detailed in the advisory, the CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) indicates a remote, low-complexity attack requiring no user interaction or privileges. Successful exploitation results in a total impact on confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update for June 2026 for remediation steps.
Affected products
- Oracle Siebel Apps - Marketing 17.0-26.5
Timeline
- 2026-06-17: disclosed: Initial disclosure by Oracle
- 2026-06-17: advisory: NVD published the CVE record