CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-46919

Critical · CVSS 9.8

Oracle Siebel CRM Cloud Applications — Improper Access Control / Authentication Bypass leading to unauthenticated RCE / Application Takeover (CWE-284, CWE-287, CWE-306)

CVSS
9.8
nvd
EPSS
KEV
No
Class
other
CWE-284, CWE-287, CWE-306

Description

Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Search profile — drives PoC discovery

Symbols Siebel Cloud ManagerSiebel CRM Cloud ApplicationsCVE-2026-46919CWE-306CWE-287CWE-284
Keywords CVE-2026-46919Siebel CRM Cloud Manager exploitSiebel CRM authentication bypassSiebel Cloud Manager unauthenticated RCEOracle Siebel CRM takeover PoCSiebel CRM 17.0 26.5 vulnerabilityOracle Siebel missing authentication exploitSiebel Cloud Manager CWE-306
Versions: 17.0 - 26.5

References

Status: enriched · ingested 2026-06-19T00:00:04.000Z · profiled 2026-06-19T00:30:04.000Z