Executive brief
Oracle Siebel CRM Cloud Applications is a customer relationship management platform used by enterprises to manage sales, marketing, and customer service operations. A vulnerability in the Siebel Cloud Manager component allows a low-privileged attacker with network access to gain complete control over the Siebel CRM system, potentially compromising all customer data, business processes, and system availability.
Technical details
This is a privilege escalation vulnerability in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications. The vulnerability is easily exploitable and requires only network access via HTTP and low-privilege credentials, with no user interaction required. An attacker who authenticates with low privileges can escalate those privileges to achieve full system compromise, including unauthorized data access, modification of business data, and service disruption. The vulnerability affects versions 22.3 through 26.7; patches are expected to be available from Oracle.
Affected products
- Oracle Siebel CRM Cloud Applications 22.3-26.7
Timeline
- 2026-09-15: disclosed
- 2026-09-15: advisory