HarborGuardharborguardDatabase
Back to search
CRITICALCVE-2026-46884Published Modified CNA oracle

CVE-2026-46884: Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing)

Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this vulnerability can result in takeover of Siebel Apps - Marketing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Metrics

CVSS v3.1
9.8
Severity
CRITICAL
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

This is an unauthenticated remote compromise vulnerability in the Marketing component of Oracle Siebel CRM (Siebel Apps - Marketing), affecting versions 17.0 through 26.5. The vulnerability is reachable over the network via HTTP with no authentication and no user interaction required, making it trivially exploitable from any network-adjacent position. Successful exploitation results in full takeover of the affected Siebel Apps - Marketing instance, including complete loss of confidentiality, integrity, and availability. No fix versions have been published by Oracle; HarborGuard is tracking the advisory and will make a patched rebuild available the moment upstream publishes a fix.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: CVE-2026-46884 is ingested from upstream advisory feeds within minutes of publication and matched against all customer images, including custom-built images that bundle Oracle Siebel CRM components, in both registry scans and active CI/CD pipeline checks.

Available
Triage

HarborGuard scores this vulnerability at CVSS 9.8 (Critical) and weights it against each environment's compliance policy to determine routing priority; findings are dispatched to the appropriate team inbox within the customer org based on image ownership and policy configuration.

Available
Patch

Because no fix version has been published by Oracle, HarborGuard re-evaluates the advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment an upstream fix is released. In the interim, the finding remains open and continuously visible in each environment's vulnerability dashboard.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the Siebel Apps - Marketing service over the network via HTTP; no local access or physical proximity is needed.

  • AuthenticationNot required

    No credentials of any privilege level are required; the attacker can interact with the vulnerable endpoint as an anonymous user.

  • Victim interactionNot required

    Exploitation is entirely attacker-driven and requires no action from any user of the affected system.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layout, or other unpredictable environmental factors.

Blast Radius

  • A successful attacker reads all data accessible to the Siebel Apps - Marketing component, including campaign records, customer contact data, and stored credentials or session tokens.
  • The attacker can modify or delete persisted marketing data, campaign configurations, and associated database records.
  • The attacker can crash or render the Siebel Apps - Marketing service completely unavailable to legitimate users.
  • Full application takeover means the attacker can pivot further into backend systems or infrastructure reachable from the compromised Siebel instance.

How HarborGuard Handles This

Available on HarborGuard: because Oracle has not yet published a fix for CVE-2026-46884, the recommended immediate action for customers running affected images (Siebel Apps - Marketing versions 17.0 through 26.5) is to apply network-level controls, specifically restricting HTTP access to the Marketing component to known, trusted source IP ranges via Kubernetes NetworkPolicy or equivalent egress and ingress filtering, and to consider feature-flag gating or temporary takedown of the Marketing endpoint if the business permits. HarborGuard continuously re-checks the Oracle advisory on every ingest cycle; when Oracle publishes a patched version, a rebuilt image at that fix version becomes available immediately, and for customers with auto-remediation enabled, a regression-test run and a pull request against affected workloads are opened automatically. The open finding remains surfaced in each environment's vulnerability dashboard at Critical priority until a fix version is confirmed.

See how HarborGuard automates this
Affected packages
  • Oracle Corporation / Siebel Apps - Marketing
    ≤ 26.5
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References