Junglewise Threat Intelligence

CVE-2026-70855: Oracle Siebel Apps Self Service cross-site request forgery

CVE-2026-70855 · Severity: critical · CVSS 9.3 · Published 2026-08-18

Vendors: Oracle.

Executive brief

Oracle Siebel Apps Self Service is a customer-facing portal component of Siebel CRM used for support and training requests. An unauthenticated attacker can exploit a vulnerability to trick authenticated users into performing unauthorized actions, resulting in unauthorized data modification, deletion, or access to sensitive customer information.

Technical details

This is an easily exploitable vulnerability in the Siebel Apps Self Service component (affecting versions 17.0–26.6) that requires user interaction from a non-attacker user. The vulnerability allows unauthenticated network attackers to exploit the flaw via HTTP, likely a cross-site request forgery (CSRF) or related web vulnerability. Successful exploitation results in unauthorized creation, deletion, or modification of critical data and confidentiality violations. The scope is marked as changed, indicating that while the flaw resides in Siebel Apps Self Service, successful attacks can significantly impact other connected products in the Siebel suite. Patches are expected to be available from Oracle following the published advisory date.

Affected products

  • Oracle Siebel Apps Self Service 17.0 to 26.6

Timeline

  • 2026-08-18: disclosed

References

Related threats