Executive brief
Oracle Siebel Apps - Self Service is a customer relationship management application used to manage helpdesk and training operations. A low-privileged attacker with network access can exploit this vulnerability to gain complete control over the application, potentially compromising customer data, disrupting service availability, and enabling unauthorized administrative actions.
Technical details
This is a privilege escalation vulnerability in the Helpdesk/Training component of Oracle Siebel Apps - Self Service. The vulnerability is exploitable over the network via HTTP by an attacker with low-level user credentials; no additional user interaction or complex configuration is required. Successful exploitation allows an attacker to achieve complete compromise with high impact to confidentiality, integrity, and availability. Affected versions range from 17.0 through 26.7; patches have been released by Oracle as part of their security updates.
Affected products
- Oracle Siebel Apps - Self Service 17.0 to 26.7
Timeline
- 2026-09-15: disclosed: Published in Oracle Security Alerts
- 2026-09-15: patched: Patches made available via Oracle Critical Patch Update