CVE-2026-46885: High severity Oracle Siebel CRM Integration vulnerability
Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: EAI). Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Integration. Successful attacks of this vulnerability can result in takeover of Siebel CRM Integration. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker needs network access to the affected Siebel CRM Integration HTTP interface and valid low-privileged credentials. No user interaction is required.
Which deployments are affected?
The affected component is EAI in Oracle Siebel CRM Integration. Supported affected versions are 17.0 through 26.5.
What is the potential impact of successful exploitation?
Successful exploitation can allow takeover of Siebel CRM Integration, with high impact to confidentiality, integrity, and availability.