Executive brief
Oracle Siebel CRM is a customer relationship management platform used to manage sales, service, and marketing operations. A privilege escalation vulnerability in the Server Infrastructure component allows a high-privilege attacker to gain complete control of the system and potentially compromise related systems through scope change, resulting in total loss of confidentiality, integrity, and availability.
Technical details
This is a privilege escalation vulnerability in the Server Infrastructure component of Oracle Siebel CRM Deployment (versions 17.0–26.7). The vulnerability requires an attacker to have high-level privileges and network access via HTTP; no special preconditions or user interaction are needed beyond these. Successful exploitation allows a high-privileged attacker to achieve complete system compromise with scope change, affecting confidentiality, integrity, and availability across Siebel CRM Deployment and potentially related products. The CVSS 3.1 vector (AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H) reflects network accessibility and high complexity with high-privilege requirements. Patch status and further technical details are not publicly available at this time.
Affected products
- Oracle Siebel CRM Deployment 17.0–26.7
Timeline
- 2026-09-15: disclosed