Executive brief
Oracle Siebel CRM Deployment is a critical enterprise customer relationship management platform used to manage customer interactions and business operations. An unauthenticated network attacker can exploit a difficult-to-exploit vulnerability in the Server Infrastructure component to gain complete control of the Siebel CRM Deployment system, potentially compromising customer data, operational continuity, and system integrity.
Technical details
This is a network-accessible vulnerability in the Server Infrastructure component of Oracle Siebel CRM Deployment (versions 17.0–26.7) that requires no authentication and no user interaction to exploit. While classified as difficult to exploit, successful attacks can result in complete system compromise including confidentiality, integrity, and availability impacts. The vulnerability is accessible over TCP and allows unauthenticated attackers to achieve remote code execution or equivalent takeover of the affected system. Patches have been made available via Oracle's October 2026 Critical Patch Update cycle.
Affected products
- Oracle Siebel CRM Deployment 17.0–26.7
Timeline
- 2026-09-15: disclosed
- 2026-10: patched: Oracle Critical Patch Update