Executive brief
Oracle Siebel CRM is a customer relationship management platform used by enterprises to manage sales, marketing, and service operations. A privilege escalation vulnerability in the Server Infrastructure component allows a low-privileged local user with system access to gain complete control of the Siebel CRM deployment, potentially exposing or corrupting customer data and disrupting business operations.
Technical details
This is a local privilege escalation vulnerability in the Siebel CRM Deployment Server Infrastructure component affecting versions 17.0 through 26.7. The vulnerability requires local access and low-privilege credentials but is easily exploitable with no user interaction needed. A successful attack allows an attacker to compromise the Siebel CRM Deployment entirely, achieving full confidentiality, integrity, and availability impact. The CVSS 3.1 vector (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) reflects local attack vector, low complexity, low privilege requirements, and high impact across all security dimensions. Patch availability status is not explicitly stated in the advisory.
Affected products
- Oracle Siebel CRM 17.0-26.7
Timeline
- 2026-09-15: disclosed