Junglewise Threat Intelligence

CVE-2026-73965: Oracle Siebel CRM unauthorized data access in Cloud Gateway

CVE-2026-73965 · Severity: medium · CVSS 6.8 · Published 2026-09-15

Executive brief

Oracle Siebel CRM is a customer relationship management system used by enterprises to manage sales, service, and marketing operations. A vulnerability in the Cloud Gateway component allows a low-privileged network attacker to read, create, modify, or delete sensitive customer data and business records without authorization, potentially exposing confidential client information and disrupting critical business processes.

Technical details

This vulnerability in the Siebel CRM Deployment Cloud Gateway component allows an authenticated attacker with low privileges to bypass authorization controls via HTTP requests. The attack is difficult to exploit but requires network access and valid user credentials; no user interaction is needed. Successful exploitation enables unauthorized read, create, update, and delete access to sensitive business data. The vulnerability affects versions 17.0 through 26.7 of Siebel CRM Deployment. Patches are expected to be available from Oracle via their security alerts portal.

Affected products

  • Oracle Siebel CRM 17.0–26.7

Timeline

  • 2026-09-15: disclosed

References

Related threats