Skip to content
OracleCVE-2026-47011

Siebel CRM Deployment: data exposure via Application Interface

Low2.6CVE-2026-47011 · Published Jul 21, 2026 · updated Aug 5, 2026

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Application Interface). Supported versions that are affected are 17.0-26.4. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 2.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N).

Oracle advisory

Affected versions

PackageAffectedFixed in
Siebel CRM Deployment
Product
>= 17.0, <= 26.4No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-203

More Oracle advisories

All Oracle
Advisory
Oracle HRMS (US): takeover via Internal Operations
High7.8Jul 21
Oracle HRMS (US): data exposure via Internal Operations
Medium6.5Jul 21
Oracle Work in Process: data tampering via Internal Operations
Medium5.4Jul 21
Oracle HRMS (US): data tampering via US Payroll Year End
High7.1Jul 21
Oracle HRMS (UK): data exposure via UK Payroll
High7.7Jul 21
Oracle Java SE: takeover via Install
High7.8Jul 21

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.