Executive brief
Oracle Siebel CRM is a customer relationship management platform used by enterprises to manage sales, service, and customer data. An unauthenticated attacker can bypass security controls via network HTTP requests to gain unauthorized access to sensitive customer and business data stored in the system. This could result in exposure of confidential customer records, sales pipeline information, and other critical business data.
Technical details
This vulnerability is an unauthenticated network-accessible authentication bypass affecting the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications. The vulnerability allows an attacker to access the system without valid credentials via HTTP network requests, with no user interaction required or authentication prerequisites. Successful exploitation grants unauthorized access to all data accessible through Siebel CRM Cloud Applications, with high confidentiality impact. The vulnerability affects versions 22.3 through 26.7; patching information should be obtained from Oracle security advisories.
Affected products
- Oracle Siebel CRM Cloud Applications 22.3-26.7
Timeline
- 2026-09-15: disclosed