Executive brief
Oracle Siebel CRM Cloud Applications, a platform used by businesses to manage customer relationships and sales data, contains a vulnerability in its Cloud Manager component. An unauthorized person can exploit this flaw over the internet to gain access to sensitive business information. This could lead to the exposure of critical customer data or proprietary company records stored within the CRM system.
Technical details
A vulnerability in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications allows an unauthenticated attacker to compromise the system via HTTP. The flaw is categorized as easily exploitable and requires no user interaction or special privileges. Successful exploitation results in unauthorized access to critical data or complete access to all accessible data within the Siebel CRM Cloud Applications environment. The vulnerability affects supported versions 22.3 through 26.5. Oracle has addressed this issue in the July 2026 Critical Patch Update.
Affected products
- Oracle Siebel CRM Cloud Applications 22.3-26.5
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released