CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-46887

Critical · CVSS 9.8

Oracle Siebel CRM - Siebel Apps Marketing — Improper Access Control / Unauthenticated Remote Takeover (CWE-284)

CVSS
9.8
nvd
EPSS
KEV
No
Class
other
CWE-284

Description

Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this vulnerability can result in takeover of Siebel Apps - Marketing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Search profile — drives PoC discovery

Symbols Siebel Apps - MarketingMarketing componentOracle Siebel CRMHTTP unauthenticatednetwork access
Keywords CVE-2026-46887Oracle Siebel CRMSiebel Marketingunauthenticated RCESiebel Apps Marketing exploitOracle Siebel takeoverCWE-284 SiebelOracle Critical Patch Update June 2026Siebel 17.0 26.5 vulnerabilitySiebel Marketing PoC
Versions: 17.0 - 26.5

References

Status: enriched · ingested 2026-06-19T00:00:04.000Z · profiled 2026-06-19T00:30:04.000Z