CVE-2026-47036: Critical severity Oracle Siebel CRM Development vulnerability
Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Siebel Approval Manager). Supported versions that are affected are 17.0-26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Development. Successful attacks of this vulnerability can result in takeover of Siebel CRM Development. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
Which deployments should be prioritized for assessment?
Prioritize Oracle Siebel CRM Development deployments that use the Siebel Approval Manager component and run supported versions 17.0 through 26.3. Exposure is relevant where an attacker can reach the product over HTTP.
Does exploitation require authentication or user interaction?
No. The vulnerability is described as exploitable by an unauthenticated attacker with network access via HTTP, with no user interaction required.
What could an attacker achieve if exploitation succeeds?
Successful exploitation can result in takeover of Siebel CRM Development. The stated impacts include high compromise of confidentiality, integrity, and availability.