Executive brief
Oracle Siebel CRM Cloud Applications, a customer relationship management platform used for enterprise sales and service operations, contains a vulnerability in its Cloud Manager component that allows remote attackers without credentials to gain unauthorized access via standard HTTP connections. Successful exploitation enables attackers to view, modify, or delete sensitive customer and business data stored within the CRM system without authentication, potentially exposing confidential customer information and disrupting critical business operations.
Technical details
The vulnerability is an easily exploitable authentication bypass or access control flaw in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications. The vulnerability is reachable over the network via HTTP and requires no authentication, credentials, or user interaction to exploit. An unauthenticated network attacker can achieve high-impact confidentiality compromise (read access to critical data) and limited integrity impact (unauthorized modification or deletion of some accessible data). Affected versions range from 22.3 through 26.7. As of the advisory date (September 2026), the vulnerability has not been reported as actively exploited in the wild.
Affected products
- Oracle Siebel CRM Cloud Applications 22.3-26.7
Timeline
- 2026-09-15: disclosed