Junglewise Threat Intelligence

CVE-2026-46890: Oracle Siebel CRM improper access control in Marketing component

CVE-2026-46890 · Severity: critical · CVSS 9.8 · Published 2026-06-17

Technologies: Oracle Siebel Apps - Marketing. Vendors: Oracle.

Executive brief

A critical vulnerability has been identified in Oracle Siebel CRM's Marketing component, which is used by organizations to manage customer relationships and marketing campaigns. This flaw allows an unauthorized person to gain full control over the marketing application over the internet without needing a username or password. An attacker could potentially steal sensitive customer data, modify marketing records, or disrupt business operations.

Technical details

This vulnerability in the Marketing component of Oracle Siebel CRM is classified under improper access control and missing authentication (CWE-284, CWE-306). It is easily exploitable by an unauthenticated attacker with network access via HTTP. The flaw allows for a complete takeover of the Siebel Apps - Marketing environment, impacting confidentiality, integrity, and availability. The vulnerability affects supported versions 17.0 through 26.5. Oracle has addressed this in their June 2026 Critical Patch Update.

Affected products

  • Oracle Siebel Apps - Marketing 17.0-26.5

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats