Executive brief
A vulnerability in Oracle's Siebel CRM Cloud Applications (component: Siebel Cloud Manager) allows a high-privileged attacker with access to the infrastructure to compromise the system and gain unauthorized access to critical business data. An attacker exploiting this flaw could read, create, delete, or modify customer records and other sensitive information stored in Siebel CRM, affecting the confidentiality and integrity of all accessible customer data.
Technical details
A privilege escalation or data access vulnerability exists in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications. The flaw requires local access to the infrastructure and high privileges to exploit, but once compromised, allows complete unauthorized access to confidential and modifiable data within the application and potentially other connected systems (scope change). The vulnerability affects versions 22.3 through 26.7. The vulnerability has no known public exploits in the wild as of the publication date. Patch or upgrade availability should be verified through Oracle's security updates.
Affected products
- Oracle Siebel CRM Cloud Applications 22.3-26.7
Timeline
- 2026-09-15: disclosed