Executive brief
Oracle Siebel CRM is a customer relationship management platform used to manage business operations and customer interactions. A vulnerability in the Siebel CRM Deployment product allows a high-privileged attacker with network access to fully compromise the system, potentially leading to takeover of the entire Siebel CRM environment and exposure of sensitive customer and business data.
Technical details
An easily exploitable vulnerability exists in the Server Infrastructure component of Oracle Siebel CRM Deployment (versions 17.0–26.7). The vulnerability requires high-level privileges and network access via TCP to exploit. Successful exploitation results in complete system compromise with impacts to confidentiality, integrity, and availability. Oracle has released patches to address this issue; see the published security advisory for patched versions and remediation guidance.
Affected products
- Oracle Siebel CRM Deployment 17.0–26.7
Timeline
- 2026-09-15: disclosed: Published by Oracle in September 2026 security alert