Executive brief
A vulnerability in Oracle Siebel Cloud Manager allows a user with low-level access to the underlying server infrastructure to take full control of the Siebel CRM application. Siebel CRM is used by large organizations to manage customer relationships and sensitive business data. A successful exploit could lead to a total compromise of the application, potentially allowing the attacker to access customer records or disrupt business operations across multiple connected systems.
Technical details
An improper access control vulnerability (CWE-284) exists in the Siebel Cloud Manager component of Oracle Siebel CRM versions 17.0 through 26.5. The flaw is easily exploitable by a low-privileged attacker who has local logon access to the infrastructure where the application executes. Because the vulnerability involves a 'scope change' (CVSS S:C), an attacker can leverage this access to impact components beyond the immediate Siebel environment. Successful exploitation results in a complete takeover of the Siebel CRM Cloud Applications, impacting confidentiality, integrity, and availability. Users are advised to refer to the Oracle June 2026 security alert for patching information.
Affected products
- Oracle Siebel CRM Cloud Applications 17.0-26.5
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory