Executive brief
Oracle Siebel CRM Integration is a customer relationship management platform that stores and manages critical business data about customers and transactions. An unauthenticated attacker can exploit a vulnerability in the REST component to gain unauthorized access to sensitive customer data without any authentication or user interaction, potentially exposing confidential business information.
Technical details
This vulnerability is an unauthenticated authentication bypass in the REST API component of Oracle Siebel CRM Integration. The vulnerability is easily exploitable, requires only network access via HTTP, and allows an unauthenticated remote attacker to read sensitive data. Versions 17.0 through 26.6 are affected. Successful exploitation grants unauthorized access to critical data or complete read access to all CRM data accessible through the REST interface. The primary impact is confidentiality (unauthorized data access); there is no integrity or availability impact.
Affected products
- Oracle Siebel CRM Integration 17.0-26.6
Timeline
- 2026-08-18: disclosed