Description
Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this vulnerability can result in takeover of Siebel Apps - Marketing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-06-16
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle Siebel Apps Marketing allows an unauthenticated attacker with network access via HTTP to take over the application. Because the flaw provides control over the system without requiring prior authentication, an attacker can read, modify, or delete data and potentially execute arbitrary code. The severity is reflected in a CVSS base score of 9.8, indicating high impacts on confidentiality, integrity, and availability.

Affected Systems

Oracle Siebel Apps Marketing versions from 17.0 through 26.5 are affected. The product is an integral component of Oracle Siebel CRM’s marketing functionality, and any deployment of these versions is at risk.

Risk and Exploitability

The vulnerability is assigned a low EPSS score of less than 1 %, suggesting that, while highly destructive, current exploitation activity is limited. It is not listed in the CISA KEV catalog. The attack vector is via the public HTTP interface and requires no prior authentication. Once accessed, the flaw can be leveraged to achieve full system takeover, with no constraints on the environment or prerequisite compromises.

Generated by OpenCVE AI on June 17, 2026 at 19:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle-published patch for CVE-2026-46890 or upgrade to an unaffected version of Siebel Apps Marketing beyond 26.5.
  • Disable or restrict HTTP access to the Siebel Marketing application on networks that do not require it, ensuring that the affected interface is not exposed to untrusted traffic.
  • Implement network segmentation and strict firewall rules to block unrestricted direct access to the Siebel Marketing ports, and enforce strong authentication and authorization checks where possible.

Generated by OpenCVE AI on June 17, 2026 at 19:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 17 Jun 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-287
CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this vulnerability can result in takeover of Siebel Apps - Marketing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle siebel Apps - Marketing
CPEs cpe:2.3:a:oracle:siebel_apps_-_marketing:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Apps - Marketing
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Siebel Apps - Marketing
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T13:08:43.743Z

Reserved: 2026-05-18T15:55:10.310Z

Link: CVE-2026-46890

cve-icon Vulnrichment

Updated: 2026-06-17T13:08:35.305Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-17T00:45:04Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function