Vulnerability in Oracle Siebel CRM's Self Service Affects Unauthenticated Access
CVE-2026-70855

9.3CRITICAL

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-70855?

An unauthenticated access vulnerability exists in Oracle Siebel CRM's Self Service functionality, impacting versions from 17.0 to 26.6. This vulnerability allows attackers with network access via HTTP to exploit the system, eventually leading to unauthorized actions such as creating, deleting, or modifying critical data. Successful exploitation necessitates user interaction from a victim, significantly broadening the potential impact, as attackers may gain access to all data accessible through the Siebel Apps - Self Service. As such, the integrity and confidentiality of critical information managed by the application may be compromised.

Affected Version(s)

Siebel Apps - Self Service 17.0 <= 26.6

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.