Executive brief
A critical vulnerability has been identified in Oracle Siebel CRM Cloud Applications, specifically within the Siebel Cloud Manager component. This software is used by organizations to manage customer relationships and cloud deployments. An exploit could allow an unauthorized person to take complete control of the application, potentially leading to the theft of sensitive customer data or a total shutdown of the service.
Technical details
This vulnerability is classified as a failure in improper access control and missing authentication (CWE-306, CWE-287). It resides in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications versions 17.0 through 26.5. An unauthenticated attacker can exploit this flaw over the network via HTTP without any user interaction. A successful exploit results in a complete takeover of the application, impacting confidentiality, integrity, and availability. Oracle has addressed this in their June 2026 security update.
Affected products
- Oracle Siebel CRM Cloud Applications 17.0-26.5
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle security alert published