Junglewise Threat Intelligence

CVE-2026-46925: Oracle Siebel CRM improper access control in Siebel Cloud Manager

CVE-2026-46925 · Severity: high · CVSS 8.3 · Published 2026-06-17

Technologies: Oracle Siebel CRM Cloud Applications. Vendors: Oracle.

Executive brief

A critical vulnerability exists in Oracle Siebel Cloud Manager, a tool used to manage and deploy Siebel CRM applications in cloud environments. An attacker with access to the local network segment could potentially take full control of the application. This could lead to a total loss of data confidentiality and service availability, potentially impacting other integrated business systems.

Technical details

This vulnerability (CWE-284) exists in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications. It is classified as difficult to exploit because it requires the attacker to have access to the specific physical communication segment (adjacent network) where the hardware executes. No authentication or user interaction is required for exploitation. A successful attack results in a 'scope change,' meaning the attacker can potentially impact products beyond the Siebel CRM environment itself. The exploit can lead to a complete takeover of the affected Siebel CRM Cloud Applications instance, impacting confidentiality, integrity, and availability. Affected versions range from 17.0 through 26.5.

Affected products

  • Oracle Siebel CRM Cloud Applications 17.0-26.5

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle Critical Patch Update published

References

Related threats