Junglewise Threat Intelligence

CVE-2026-47016: Oracle Siebel CRM Integration information disclosure in Event Publish and Subscribe

CVE-2026-47016 · Severity: low · CVSS 1.9 · Published 2026-07-21

Technologies: Oracle Siebel CRM Integration. Vendors: Oracle.

Executive brief

Oracle Siebel CRM Integration, a tool used to connect customer relationship management data with other business systems, contains a security vulnerability in its Event Publish and Subscribe component. An attacker with physical access to the system and high-level administrative privileges could potentially view a limited amount of sensitive data. While the risk is low due to the requirement for physical access, a successful breach could impact other connected business products.

Technical details

A vulnerability in the Event Publish and Subscribe component of Oracle Siebel CRM Integration (versions 17.0-26.4) allows for unauthorized data disclosure. The exploit is classified as difficult (AC:H) and requires the attacker to have physical access to the target system (AV:P) as well as high-level privileges (PR:H). Successful exploitation results in a scope change (S:C), meaning the impact can extend beyond the Siebel CRM Integration component to other products, though the impact is limited to low confidentiality loss (C:L). No impact to integrity or availability was reported. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Siebel CRM Integration 17.0-26.4

Timeline

  • 2026-07-21: advisory: Published by Oracle and NVD

References

Related threats