Executive brief
A critical vulnerability has been identified in Oracle Siebel CRM's Approval Manager, a component used for managing development workflows and approvals. An unauthorized person can remotely take full control of the system over the internet without needing any login credentials. This could lead to a total loss of data confidentiality, unauthorized changes to business processes, and disruption of CRM operations.
Technical details
A vulnerability in the Siebel Approval Manager component of Oracle Siebel CRM Development (versions 17.0 through 26.3) allows an unauthenticated attacker with network access via HTTP to compromise the system. The flaw is characterized as 'easily exploitable' and does not require user interaction. Successful exploitation grants the attacker full control over the Siebel CRM Development environment, impacting confidentiality, integrity, and availability (CVSS 9.8). Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Siebel CRM Development 17.0-26.3
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle
- 2026-07-21: advisory: NVD publication date