Description
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw was discovered in the Siebel CRM Cloud Applications’ Siebel Cloud Manager component that allows an unauthenticated attacker with HTTPS network access to send specially crafted requests that cause the application to hang or crash. The failure results in a complete denial of service, disabling the application for all users until it is restarted. The vulnerability does not provide confidentiality or integrity gains but fully disrupts availability.

Affected Systems

The flaw affects Oracle Corporation’s Siebel CRM Cloud Applications. Supported versions 22.3 through 26.5 are impacted. All instances of these releases, irrespective of deployment configuration, are vulnerable because the underlying component remains the same.

Risk and Exploitability

The CVSS 3.1 base score of 7.5 reflect a moderate‑to‑high impact on availability with no authentication or user interaction required. The EPSS score of <1% indicates that exploitation is currently rare, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is remote over HTTPS, requiring only network access to exposed endpoints. Because the flaw causes arbitrary process termination, an attacker that succeeds can bring the service down for all users until the application restarts. While exploitation probability is low, the high availability impact warrants prompt attention.

Generated by OpenCVE AI on August 4, 2026 at 17:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch or upgrade the Siebel CRM Cloud Applications to a version newer than 26.5 that removes the flaw.
  • Restrict inbound HTTPS traffic to the Siebel Cloud Manager services with firewall rules or reverse‑proxy access controls, limiting exposure to trusted hosts or VPN endpoints.
  • Monitor application logs for repeated crash events and configure alerts so that operators are notified promptly of denial‑of‑service attempts.

Generated by OpenCVE AI on August 4, 2026 at 17:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTPS Attack Creates Denial of Service in Oracle Siebel CRM Cloud Applications

Tue, 28 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Siebel CRM Cloud Applications Client Crash/Denial of Service via Unauthenticated HTTPS Access
Weaknesses CWE-770

Fri, 24 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Siebel CRM Cloud Applications Client Crash/Denial of Service via Unauthenticated HTTPS Access
Weaknesses CWE-770

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle siebel Crm Cloud Applications
CPEs cpe:2.3:a:oracle:siebel_crm_cloud_applications:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Cloud Applications
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Oracle Siebel Crm Siebel Crm Cloud Applications
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T16:07:59.609Z

Reserved: 2026-05-18T15:55:10.317Z

Link: CVE-2026-47018

cve-icon Vulnrichment

Updated: 2026-07-23T16:07:55.295Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:17:07.450

Modified: 2026-08-05T17:03:28.333

Link: CVE-2026-47018

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:45:03Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption