Junglewise Threat Intelligence

CVE-2026-46889: Oracle Siebel CRM improper access control in Siebel Apps - Marketing

CVE-2026-46889 · Severity: critical · CVSS 9.8 · Published 2026-06-17

Technologies: Oracle Siebel Apps - Marketing. Vendors: Oracle.

Executive brief

A critical vulnerability exists in Oracle Siebel Apps - Marketing, a component of the Siebel CRM suite used for managing marketing campaigns and customer data. An unauthenticated attacker can exploit this flaw over the network to gain full control of the application. This could lead to the theft of sensitive customer information, unauthorized modification of marketing data, or a complete disruption of marketing operations.

Technical details

This vulnerability is classified as Improper Access Control (CWE-284) within the Marketing component of Oracle Siebel CRM. It is remotely exploitable via HTTP without the need for authentication or user interaction (CVSS 9.8). Successful exploitation allows an attacker to achieve a total compromise of the Siebel Apps - Marketing environment, impacting confidentiality, integrity, and availability. The issue affects versions 17.0 through 26.5. Oracle has addressed this in the June 2026 Critical Patch Update.

Affected products

  • Oracle Siebel Apps - Marketing 17.0-26.5

Timeline

  • 2026-06-17: disclosed: Initial disclosure by Oracle
  • 2026-06-17: advisory: NVD entry published

References

Related threats