Impact
The vulnerability exists in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications and allows an attacker with low privilege who can reach the application via HTTP to accomplish a full takeover. The flaw can be exploited directly through the web interface, permitting an attacker to execute actions that compromise confidentiality, integrity, and availability of the application and its underlying data. Successful exploitation results in loss of customer data, the ability to alter business processes, and potential service disruption.
Affected Systems
Oracle Corporation’s Siebel CRM Cloud Applications – versions 22.3 to 26.6 – are impacted. All Cloud Manager deployments within that version range are vulnerable, as indicated by Oracle’s August 2026 security alert. This cloud‑based CRM platform is accessed via HTTP or HTTPS, and the issue pertains specifically to the Siebel Cloud Manager component.
Risk and Exploitability
The CVSS 3.1 base score of 8.8 indicates high severity, with full confidentiality, integrity, and availability impacts. The EPSS score is < 1%, indicating a very low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is network‑based (HTTP), with low attack complexity, low privilege required, and no user interaction needed; an automated script could therefore be effective. Organizations running the affected versions should treat this as a critical exposure until a vendor patch is applied.
OpenCVE Enrichment