Executive brief
A vulnerability in Oracle Siebel CRM Cloud Applications could allow an authorized user with low-level permissions to access sensitive business data. This flaw affects the Siebel Cloud Manager component, which is used to manage CRM deployments in cloud environments. An attacker could exploit this to gain unauthorized access to critical customer information or all data within the application, potentially impacting other integrated business systems.
Technical details
A vulnerability exists in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications (versions 22.3 through 26.5). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. The vulnerability is characterized by a 'Scope Change' (S:C), meaning an exploit can impact components beyond the immediate Siebel CRM environment. Successful exploitation results in a high confidentiality impact, allowing unauthorized access to critical data or complete access to all accessible data within the application. No user interaction is required for exploitation.
Affected products
- Oracle Siebel CRM Cloud Applications 22.3-26.5
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle
- 2026-07-21: advisory: NVD publication date