Executive brief
Oracle Siebel CRM Cloud Applications, a platform used by large organizations to manage customer relationships and sales data, contains a critical security flaw in its Cloud Manager component. An unauthorized attacker could exploit this vulnerability over the internet to gain full control of the application. A successful attack would allow the intruder to access sensitive customer data, modify business records, or disrupt critical operations.
Technical details
A vulnerability in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications (versions 17.0 through 26.5) allows for improper access control and missing authentication for critical functions (CWE-284, CWE-306). An unauthenticated attacker can exploit this over the network via HTTP. While the vulnerability is classified as difficult to exploit (High Attack Complexity), a successful attack results in a complete compromise of the application's confidentiality, integrity, and availability. This can lead to a total takeover of the Siebel CRM Cloud environment. Users are advised to refer to the Oracle June 2026 security alert for patching information.
Affected products
- Oracle Siebel CRM Cloud Applications 17.0-26.5
Timeline
- 2026-06-17: disclosed: Initial disclosure by Oracle
- 2026-06-17: advisory: NVD publication date