HIGH 8.1

CVE-2026-46920: Oracle Siebel CRM Cloud Manager Unauthenticated Remote Takeover

A vulnerability in Oracle's Siebel CRM Cloud Manager allows an unauthenticated attacker with network access to take over a Siebel CRM Cloud Applications deployment. The attack requires some specific conditions to be met (high attack complexity) but does not require user interaction or valid credentials. If successfully exploited, an attacker gains full control over confidentiality, integrity, and availability of the affected CRM system. Versions 17.0 through 26.5 are vulnerable.

Source data · NVD / CISA · public domain

CVSS
3.1 · 8.1 HIGH · CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
CWE-284, CWE-306
Affected products
1 configuration(s)
Published / Modified
2026-06-17 / 2026-06-18

NVD description (verbatim)

Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 17.0-26.5. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

1 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

This vulnerability resides in the Siebel Cloud Manager component and stems from improper access controls and insufficient authentication mechanisms (CWE-284: Improper Access Control, CWE-306: Missing Authentication for Critical Function). An unauthenticated network attacker can exploit the HTTP interface to achieve complete system compromise. The CVSS 3.1 score of 8.1 reflects the high impact potential (all three impact categories affected) balanced against the elevated attack complexity, indicating that while exploitation is feasible, it requires careful preparation or specific environmental conditions to succeed.

Business impact

Full compromise of a Siebel CRM deployment exposes critical business data—customer records, transaction history, sales pipelines, and configuration details—to unauthorized access and modification. An attacker could alter customer data, manipulate transactions, disrupt operations, or exfiltrate sensitive information. The ability to take over the system without credentials represents a significant operational and compliance risk, particularly for organizations using Siebel CRM to manage regulated customer relationships or financial data.

Affected systems

Oracle Siebel CRM Cloud Applications running Siebel Cloud Manager component versions 17.0 through 26.5 are affected. This covers a five-year span of Siebel releases. Organizations should verify their deployed version against Oracle's documentation. Cloud-hosted Siebel deployments managed through the Cloud Manager component are at highest risk. On-premises Siebel installations using affected component versions are also in scope.

Exploitability

While the vulnerability is classified as 'difficult to exploit' (reflected in the High attack complexity component of the CVSS vector), it requires only network access and no authentication. An attacker must be able to reach the HTTP interface and likely needs to satisfy specific conditions or environmental factors to trigger the vulnerability. The absence of user interaction as a requirement and the network accessibility increase the threat; the difficulty lies in crafting the exploit, not in bypass of security controls.

Remediation

Apply the security patch provided by Oracle for Siebel Cloud Manager. Verify the patch version against Oracle's official security advisory. Until patches are applied, restrict network access to the Siebel Cloud Manager HTTP interface through firewall rules, network segmentation, or WAF policies. Limit access to known administrative networks or IP ranges. Monitor for suspicious HTTP requests to the Cloud Manager endpoints.

Patch guidance

Consult Oracle's official Siebel CRM security advisory for the specific patch version applicable to your release line (17.0–26.5). Patch availability and testing procedures vary by release. Prioritize patching in non-production environments first to verify compatibility with your configuration and integrations. Post-patch validation should include functional testing of critical CRM workflows and API endpoints. Establish a timeline to apply patches to production within 2–4 weeks depending on your change management process and operational criticality.

Detection guidance

Monitor HTTP access logs to the Siebel Cloud Manager interface for unusual patterns: requests from unexpected source IPs, anomalous request sequences, or probing behavior targeting authentication endpoints. Implement network-based detection for known attack signatures related to this vulnerability (verify availability in your IDS/IPS vendor's threat feed). Log and alert on authentication failures followed by successful privileged actions. Enable verbose logging in Siebel Cloud Manager to capture access attempts and configuration changes. Review system logs for unauthorized login sessions or privilege escalations.

Why prioritize this

This vulnerability should be prioritized for immediate patching due to its high CVSS score (8.1), unauthenticated attack vector, and complete system compromise impact. While exploit difficulty is elevated, the lack of authentication requirements and network accessibility mean attackers can probe for and exploit this flaw at scale. Siebel CRM typically holds sensitive customer and transaction data critical to business operations. The five-year affected version span indicates a broad installed base. Organizations should treat this as urgent, though the 'difficult to exploit' classification allows time for orderly patching rather than emergency response.

Risk score, explained

The CVSS 3.1 base score of 8.1 (HIGH severity) reflects a high-impact vulnerability with barriers to exploitation. The score comprises: AV:N (network-accessible, no physical presence required), AC:H (attack complexity is high, indicating specific conditions or knowledge required), PR:N (no privileges needed), UI:N (no user interaction), S:U (scope unchanged), and all three impact metrics at High (C:H, I:H, A:H). The elevated complexity keeps the score from being critical but does not diminish the severity of a successful attack. Organizations operating Siebel CRM at scale should treat an 8.1 score as requiring urgent but methodical remediation.

Frequently asked questions

Does this vulnerability affect on-premises Siebel CRM installations?

Yes. Any Siebel CRM Cloud Applications deployment running the Siebel Cloud Manager component in versions 17.0–26.5 is affected, whether hosted on-premises, in Oracle Cloud Infrastructure, or in a third-party data center. The vulnerability is specific to the Cloud Manager component, not all Siebel functionality.

Is there active exploit code in the wild for this vulnerability?

As of the published date, this vulnerability is not listed in the KEV (Known Exploited Vulnerabilities) catalog, indicating no public evidence of active exploitation at the time of publication. However, organizations should apply patches promptly rather than relying on the absence of current exploits.

Can network segmentation reduce the risk while we prepare patches?

Yes. Restricting HTTP/HTTPS access to the Siebel Cloud Manager interface to known administrative networks, VPNs, or bastion hosts significantly reduces the attack surface. Combined with WAF rules and IP allowlisting, network controls can buy time for testing and deployment of patches, but are not a substitute for patching.

Which versions are safe to run?

Oracle has not released information indicating safe versions beyond those affected (17.0–26.5). Consult Oracle's security advisory for patched version numbers and upgrade guidance for versions outside the affected range. Verify patch applicability for your specific Siebel release line before deployment.

This analysis is based on the published CVE description and CVSS vector as of the date of publication. No exploit code or weaponized attack details are provided. Organizations should verify patch availability, version applicability, and compatibility with their specific Siebel CRM configuration by consulting Oracle's official security advisory. Risk assessment should account for your organization's network topology, data sensitivity, and operational criticality. This document does not constitute professional security advice and should be reviewed by your security and compliance teams in the context of your specific environment. Source: NVD (public-domain), retrieved 2026-07-25. Analysis generated by SEC.co (claude-haiku-4-5).