Executive brief
Oracle Siebel CRM Integration is a customer relationship management platform used by enterprises to manage sales, service, and marketing operations. An unauthenticated attacker can gain unauthorized access to sensitive customer and operational data through an easily exploitable network vulnerability, potentially exposing confidential business information and customer records.
Technical details
This is an authentication bypass vulnerability in the Open Integration component of Siebel CRM Integration. An unauthenticated attacker with network access can exploit the vulnerability via HTTP requests without requiring user interaction or additional privileges. The weakness allows an attacker to bypass authentication controls and gain unauthorized access to critical data stored within Siebel CRM Integration. No code execution or integrity compromise is possible, but confidentiality of all accessible data is at risk. Affected versions are 25.12 through 26.7.
Affected products
- Oracle Siebel CRM Integration 25.12-26.7
Timeline
- 2026-09-15: disclosed