CVE-2026-46925: High severity Oracle Siebel CRM Cloud Applications vulnerability
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 17.0-26.5. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications. While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
Who is realistically exposed to this vulnerability?
Affected deployments are Oracle Siebel CRM Cloud Applications running supported versions 17.0 through 26.5. Exploitation requires access to the physical communication segment connected to the hardware hosting the application, so exposure is limited to attackers able to reach that adjacent network segment.
Does an attacker need an account or user interaction to exploit it?
No. The vulnerability is exploitable without authentication or privileges, and it does not require user interaction. However, exploitation is described as difficult and requires adjacent-network access.
What is the likely impact of successful exploitation?
A successful attack can result in takeover of Siebel CRM Cloud Applications, with high impact to confidentiality, integrity, and availability. The scope change also indicates that attacks may significantly affect additional products.
How can I tell whether my environment is affected?
Identify Siebel CRM Cloud Applications deployments using Siebel Cloud Manager and determine whether their supported version is within 17.0 through 26.5. Also assess whether untrusted parties can access the physical communication segment attached to the hosting hardware.