Executive brief
A vulnerability exists in Oracle Siebel CRM Cloud Applications, a platform used by businesses to manage customer relationships and sales operations. An attacker can remotely exploit this flaw to cause the system to crash or become unresponsive. This could lead to a total service outage, preventing employees from accessing critical customer data and disrupting business operations.
Technical details
A vulnerability in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications (versions 22.3 through 26.5) allows for a denial-of-service (DoS) attack. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTPS. Successful exploitation allows the attacker to cause a frequently repeatable crash or a complete system hang, impacting the availability of the CRM environment. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Siebel CRM Cloud Applications 22.3-26.5
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this vulnerability.
- 2026-07-21: disclosed