CVE-2026-46889
Critical · CVSS 9.8Oracle Siebel CRM - Siebel Apps Marketing — Improper Access Control (Unauthenticated Remote Takeover via HTTP)
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-284
Description
Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this vulnerability can result in takeover of Siebel Apps - Marketing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Search profile — drives PoC discovery
Symbols Siebel Apps - MarketingSiebelMarketingOracle Siebel CRMCRM Marketing componentHTTP unauthenticatedCWE-284
Keywords CVE-2026-46889Oracle Siebel CRMSiebel Apps Marketingunauthenticated RCESiebel Marketing takeoverOracle Siebel exploitCVE-2026-46889 PoCSiebel CRM 17.0 26.5 vulnerabilityOracle Siebel HTTP exploitCWE-284 Siebel
Versions: 17.0 - 26.5
References
Status: enriched · ingested 2026-06-19T00:00:04.000Z · profiled 2026-06-19T00:30:04.000Z