Vulnerability in Oracle Siebel CRM's Self Service Affects Unauthenticated Access
CVE-2026-70855
9.3CRITICAL
What is CVE-2026-70855?
An unauthenticated access vulnerability exists in Oracle Siebel CRM's Self Service functionality, impacting versions from 17.0 to 26.6. This vulnerability allows attackers with network access via HTTP to exploit the system, eventually leading to unauthorized actions such as creating, deleting, or modifying critical data. Successful exploitation necessitates user interaction from a victim, significantly broadening the potential impact, as attackers may gain access to all data accessible through the Siebel Apps - Self Service. As such, the integrity and confidentiality of critical information managed by the application may be compromised.
Affected Version(s)
Siebel Apps - Self Service 17.0 <= 26.6