Executive brief
Oracle's Siebel CRM Cloud Manager is a component that manages Siebel CRM Cloud Applications, which are widely used for customer relationship management across enterprises. A low-privileged attacker with network access can exploit this vulnerability to read sensitive customer data and modify business records without authorization, affecting data confidentiality and integrity across versions 22.3 through 26.7.
Technical details
This vulnerability in Siebel Cloud Manager allows low-privileged, network-authenticated attackers to bypass data access controls via HTTP. The flaw is easily exploitable (low attack complexity) and requires only basic user privileges to trigger. Successful exploitation results in unauthorized read access to a subset of CRM data and unauthorized update, insert, or delete operations on some accessible data, with scope change indicating potential impact on connected systems. No evidence of active exploitation or available patches is documented at this time.
Affected products
- Oracle Siebel CRM Cloud Applications 22.3-26.7
Timeline
- 2026-09-15: disclosed