Junglewise Threat Intelligence

CVE-2026-73966: Oracle Siebel CRM Apps Marketing privilege escalation

CVE-2026-73966 · Severity: high · CVSS 7.2 · Published 2026-09-15

Executive brief

Oracle Siebel CRM is a customer relationship management platform used by enterprises to manage sales, marketing, and customer service operations. A privilege escalation vulnerability in the Marketing component allows a high-privileged attacker with network access to take complete control of the affected application, potentially compromising all customer data and business operations managed through the marketing system.

Technical details

This vulnerability in the Siebel Apps Marketing component is an exploitable privilege escalation that allows high-privileged attackers with network access via HTTP to compromise the application. The vulnerability can result in a complete takeover (arbitrary code execution or full system compromise). Attack vector is network-based with low complexity, no user interaction required, and impacts confidentiality, integrity, and availability. The vulnerability affects versions 17.0 through 26.7 of Oracle Siebel CRM. A patch or mitigation is likely available but details are not yet fully accessible in public sources.

Affected products

  • Oracle Siebel CRM Apps Marketing 17.0-26.7

Timeline

  • 2026-09-15: disclosed

References