Executive brief
Oracle Siebel CRM is a widely-deployed enterprise customer relationship management system used to manage sales, service, and marketing operations. A vulnerability in its Server Infrastructure component allows a low-privileged user with local system access to gain complete control over the Siebel CRM Deployment, potentially compromising customer data, business continuity, and the integrity of all CRM operations.
Technical details
This local privilege escalation vulnerability in Oracle Siebel CRM's Server Infrastructure component (versions 17.0–26.7) requires the attacker to have low-level logon privileges and local access to the infrastructure where Siebel CRM Deployment executes. The vulnerability is easily exploitable and requires no user interaction or elevated initial privileges. Successful exploitation allows an attacker to achieve complete compromise of the Siebel CRM Deployment system, gaining unauthorized control over confidentiality, integrity, and availability of CRM data and services. Patches are expected from Oracle as part of their regular security release cycle.
Affected products
- Oracle Siebel CRM 17.0 to 26.7
Timeline
- 2026-09-15: disclosed