Executive brief
A vulnerability in Oracle Siebel Cloud Manager allows an attacker with basic user credentials to take full control of the Siebel CRM Cloud environment. Siebel CRM is used by organizations to manage customer relationships and business processes; a successful exploit could lead to the theft of sensitive customer data, unauthorized modification of business records, and total service disruption. This issue is easily exploitable over the network via HTTP.
Technical details
This vulnerability exists in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications (versions 17.0 through 26.5). It is classified as an improper access control or privilege management issue (CWE-269, CWE-284). An attacker with low-privileged user access can exploit this flaw over the network via HTTP without any user interaction. Successful exploitation allows for a complete takeover of the Siebel CRM Cloud Applications, impacting confidentiality, integrity, and availability. Oracle has addressed this in the June 2026 security alert.
Affected products
- Oracle Siebel CRM Cloud Applications 17.0-26.5
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle Critical Patch Update published