Executive brief
Oracle Siebel CRM is a widely-deployed customer relationship management platform used by enterprises to manage sales, service, and customer interactions. A flaw in the Server Infrastructure component allows a low-privileged network attacker to gain complete control of the entire Siebel CRM system, potentially exposing all customer data, transaction history, and business-critical information stored within it.
Technical details
This vulnerability in the Siebel CRM Deployment Server Infrastructure component is easily exploitable and allows a low-privileged attacker with network access via HTTPS to achieve complete system compromise. The attack requires minimal preconditions—only a low-privilege account and network reachability—and does not require user interaction. Successful exploitation results in full takeover of the Siebel CRM Deployment, granting the attacker unrestricted access to confidentiality, integrity, and availability of the system and data. The vulnerability affects versions 17.0 through 26.7; patch availability should be confirmed with Oracle.
Affected products
- Oracle Siebel CRM Deployment 17.0-26.7
Timeline
- 2026-09-15: disclosed