HIGH 8.3

CVE-2026-46925: Oracle Siebel CRM Cloud Manager Improper Access Control

A vulnerability exists in Oracle Siebel CRM Cloud Applications (versions 17.0 through 26.5) that allows an unauthenticated attacker with physical access to the network segment where the application runs to take over the system entirely. While the flaw is in Siebel itself, successful exploitation can impact other connected systems. The attack is difficult to execute in practice, but if successful, gives an attacker complete control over confidentiality, integrity, and availability of the application.

Source data · NVD / CISA · public domain

CVSS
3.1 · 8.3 HIGH · CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Weaknesses (CWE)
CWE-284
Affected products
1 configuration(s)
Published / Modified
2026-06-17 / 2026-06-18

NVD description (verbatim)

Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 17.0-26.5. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications. While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).

1 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-46925 is an improper access control vulnerability (CWE-284) in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications. The vulnerability requires an unauthenticated attacker to be positioned on the same physical network segment as the affected hardware. The high complexity of exploitation (AC:H) is offset by the critical impact: successful compromise results in complete system takeover with high impact across confidentiality, integrity, and availability. The scope change (S:C) indicates that while the vulnerability originates in Siebel CRM Cloud Applications, its effects can cascade to other systems in the environment.

Business impact

Successful exploitation could grant an attacker administrative control over your Siebel CRM instance, enabling data exfiltration, system manipulation, and service disruption. Given Siebel's role as a customer relationship management platform, this could expose customer data, transaction records, and business logic. The scope change dimension suggests that lateral movement to adjacent systems is possible, potentially amplifying damage across your infrastructure. Organizations should assess whether Siebel instances are internet-facing or contain sensitive customer information.

Affected systems

Oracle Siebel CRM Cloud Applications versions 17.0 through 26.5 are vulnerable. The Siebel Cloud Manager component is the attack surface. The vulnerability does not affect on-premises Siebel deployments in the same way, as the threat model requires physical network adjacency. Organizations running any version within this range on cloud infrastructure should prioritize assessment.

Exploitability

Exploitation is rated as difficult (AC:H) and requires an attacker to be on the same physical network segment as the Siebel hardware—a significant constraint that eliminates most remote attack scenarios. No authentication is required, but the attacker must have either compromised a connected device, gained physical access to the data center network, or positioned themselves within a cloud provider's network segment. These prerequisites make mass exploitation unlikely, but targeted attacks against high-value instances remain credible.

Remediation

Apply security patches from Oracle for Siebel CRM Cloud Applications as soon as they become available. Verify patch version numbers and compatibility with your current deployment through the Oracle Security Advisories page. In parallel, implement network segmentation to restrict access to the physical network segment where Siebel runs, limiting exposure to authenticated or trusted internal systems only. Review and tighten access controls to the Siebel Cloud Manager component.

Patch guidance

Consult Oracle's official security advisory for CVE-2026-46925 to identify the specific patch version for your Siebel CRM Cloud Applications release (versions 17.0–26.5). Test patches in a staging environment before production deployment, as Siebel updates can affect integrated systems. Verify that patches are applied to all instances, including development and disaster recovery environments. Enable automated patch notifications from Oracle to stay informed of cumulative fixes.

Detection guidance

Monitor network logs for unusual traffic patterns on the physical network segment containing Siebel infrastructure. Deploy intrusion detection systems to flag unauthorized access attempts to the Siebel Cloud Manager component. Review authentication logs and administrative access records for anomalies, particularly failed authentication attempts followed by successful access. Use database activity monitoring (DAM) tools to detect unexpected changes to CRM data or administrative configurations. Establish baseline traffic profiles to identify deviation that could indicate exploitation attempts.

Why prioritize this

Although exploitation is difficult and requires physical network proximity, the potential for complete system compromise (CVSS 8.3, HIGH severity) and impact on downstream systems justifies prompt attention. Siebel instances managing critical customer data or business processes should be prioritized. Organizations with cloud deployments where network isolation may be weaker should treat this as higher priority than those with well-segmented on-premises infrastructure.

Risk score, explained

The CVSS 3.1 score of 8.3 reflects the critical impact (C:H, I:H, A:H) balanced against the significant attack complexity (AC:H) and authentication-free access requirement. The scope change (S:C) elevates risk by indicating potential for lateral impact. This is a high-severity vulnerability, but the practical barrier to exploitation—physical network access—prevents it from being rated Critical.

Frequently asked questions

Do I need to be on the internet to exploit this vulnerability?

No. The attacker must be on the same physical network segment as the Siebel hardware. This rules out pure remote exploitation from the internet, but includes scenarios where an attacker has compromised a system on your internal network, gained physical data center access, or positioned themselves within a cloud provider's infrastructure.

Is this vulnerability currently being exploited in the wild?

This vulnerability has not been added to the CISA KEV (Known Exploited Vulnerabilities) catalog, which suggests no confirmed active exploitation has been reported at this time. However, organizations should assume sophisticated threat actors may develop exploits as patches roll out.

What is 'scope change' and why does it matter?

Scope change (S:C in the CVSS vector) means that while the flaw is in Siebel CRM Cloud Applications, an attacker can use it to compromise systems or data outside of Siebel itself. This increases the blast radius of an attack beyond the vulnerable application, making it more damaging.

Do on-premises Siebel deployments face the same risk as cloud deployments?

On-premises Siebel instances still require the attacker to be on the same physical network segment, but your ability to control and monitor that segment is typically greater. Cloud deployments may have weaker network isolation, depending on your provider's configuration and your own security controls. Review your network architecture with your cloud provider to confirm segmentation.

This analysis is based on Oracle's official CVE description and CVSS assessment as of the published date. Patch versions, availability timelines, and workarounds are subject to change; consult Oracle's Security Advisories for the most current guidance. This vulnerability requires physical network adjacency, which limits but does not eliminate risk—assess your own network architecture and threat model. No exploit code or proof-of-concept has been provided or endorsed by this analysis. Organizations should conduct their own risk assessment and testing in alignment with their security policies. Source: NVD (public-domain), retrieved 2026-07-25. Analysis generated by SEC.co (claude-haiku-4-5).