Executive brief
Oracle Siebel CRM is a customer relationship management platform used by enterprises to manage customer interactions and data. An unauthenticated attacker can exploit a vulnerability in the Server Infrastructure component via network access to read sensitive customer data, modify records, and insert or delete business information without proper authorization.
Technical details
The vulnerability is an unauthenticated access control flaw in the Siebel CRM Server Infrastructure component affecting versions 17.0 through 26.7. The vulnerability is easily exploitable via HTTP and requires no authentication or user interaction—an attacker on the network can directly compromise the application. Successful exploitation allows unauthorized read access to all data within Siebel CRM Deployment as well as unauthorized modification, insertion, or deletion of some accessible data. No patch information is currently available from Oracle.
Affected products
- Oracle Siebel CRM 17.0 through 26.7
Timeline
- 2026-09-15: disclosed