CVE-2026-46884: Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing)
Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this vulnerability can result in takeover of Siebel Apps - Marketing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Metrics
- CVSS v3.1
- 9.8
- Severity
- CRITICAL
- Fixed in
- —
- Affected Products
- 1
HarborGuard Analysis
Synopsis
This is an unauthenticated remote compromise vulnerability in the Marketing component of Oracle Siebel CRM (Siebel Apps - Marketing), affecting versions 17.0 through 26.5. The vulnerability is reachable over the network via HTTP with no authentication and no user interaction required, making it trivially exploitable from any network-adjacent position. Successful exploitation results in full takeover of the affected Siebel Apps - Marketing instance, including complete loss of confidentiality, integrity, and availability. No fix versions have been published by Oracle; HarborGuard is tracking the advisory and will make a patched rebuild available the moment upstream publishes a fix.
HarborGuard Coverage
Detection is available across every HarborGuard environment: CVE-2026-46884 is ingested from upstream advisory feeds within minutes of publication and matched against all customer images, including custom-built images that bundle Oracle Siebel CRM components, in both registry scans and active CI/CD pipeline checks.
AvailableHarborGuard scores this vulnerability at CVSS 9.8 (Critical) and weights it against each environment's compliance policy to determine routing priority; findings are dispatched to the appropriate team inbox within the customer org based on image ownership and policy configuration.
AvailableBecause no fix version has been published by Oracle, HarborGuard re-evaluates the advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment an upstream fix is released. In the interim, the finding remains open and continuously visible in each environment's vulnerability dashboard.
Pending upstreamExploit Conditions
- Network reachabilityRequired
The attacker must reach the Siebel Apps - Marketing service over the network via HTTP; no local access or physical proximity is needed.
- AuthenticationNot required
No credentials of any privilege level are required; the attacker can interact with the vulnerable endpoint as an anonymous user.
- Victim interactionNot required
Exploitation is entirely attacker-driven and requires no action from any user of the affected system.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layout, or other unpredictable environmental factors.
Blast Radius
- A successful attacker reads all data accessible to the Siebel Apps - Marketing component, including campaign records, customer contact data, and stored credentials or session tokens.
- The attacker can modify or delete persisted marketing data, campaign configurations, and associated database records.
- The attacker can crash or render the Siebel Apps - Marketing service completely unavailable to legitimate users.
- Full application takeover means the attacker can pivot further into backend systems or infrastructure reachable from the compromised Siebel instance.
How HarborGuard Handles This
Available on HarborGuard: because Oracle has not yet published a fix for CVE-2026-46884, the recommended immediate action for customers running affected images (Siebel Apps - Marketing versions 17.0 through 26.5) is to apply network-level controls, specifically restricting HTTP access to the Marketing component to known, trusted source IP ranges via Kubernetes NetworkPolicy or equivalent egress and ingress filtering, and to consider feature-flag gating or temporary takedown of the Marketing endpoint if the business permits. HarborGuard continuously re-checks the Oracle advisory on every ingest cycle; when Oracle publishes a patched version, a rebuilt image at that fix version becomes available immediately, and for customers with auto-remediation enabled, a regression-test run and a pull request against affected workloads are opened automatically. The open finding remains surfaced in each environment's vulnerability dashboard at Critical priority until a fix version is confirmed.
- Oracle Corporation / Siebel Apps - Marketing≤ 26.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H