Executive brief
Oracle Siebel CRM is a widely-used customer relationship management platform that organizations rely on to manage sales, service, and customer data. This vulnerability in the Server Infrastructure component allows a low-privileged user with local access to take complete control of the Siebel CRM system, compromising the confidentiality, integrity, and availability of customer data and business operations. The attack requires user interaction, but once exploited, an attacker gains full system compromise.
Technical details
This is a local privilege escalation vulnerability in the Siebel CRM Deployment Server Infrastructure component affecting versions 17.0 through 26.7. The vulnerability is easily exploitable by a low-privileged attacker with logon access to the infrastructure running Siebel CRM Deployment, and requires user interaction from another person to succeed. A successful exploit results in complete takeover of the Siebel CRM Deployment system, with impacts to confidentiality, integrity, and availability. No patch information is currently available from the provided advisory.
Affected products
- Oracle Siebel CRM 17.0-26.7
Timeline
- 2026-09-15: disclosed