SYS::ONLINE
Wasteland.
Briefs1411
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-47036 2026-07-21

CVE-2026-47036: Critical Unauthenticated Takeover Flaw in Oracle Siebel CRM

"A critical, easily exploitable vulnerability in Oracle Siebel CRM Development allows an unauthenticated remote attacker to fully compromise the affected system over HTTP."

A critical, easily exploitable vulnerability in Oracle Siebel CRM Development allows an unauthenticated remote attacker to fully compromise the affected system over HTTP.

What Is It

CVE-2026-47036 is a critical vulnerability in the Siebel CRM Development product of Oracle Siebel CRM, specifically within the Siebel Approval Manager component. According to Oracle's advisory, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via HTTP to compromise Siebel CRM Development. Successful exploitation can result in complete takeover of Siebel CRM Development.

It carries a CVSS 3.1 Base Score of 9.8 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, meaning network attack vector, low complexity, no privileges or user interaction required, and high impact to confidentiality, integrity, and availability.

Why It Matters

The combination of no authentication, no user interaction, low attack complexity, and full compromise makes this among the most severe classes of vulnerability. A successful attack yields takeover of the affected CRM environment, exposing sensitive business and customer data as well as the integrity and availability of the system. Because exploitation requires only HTTP network access, any internet-reachable or otherwise accessible instance is at high risk.

Note: No CISA KEV entry was supplied for this CVE, so active exploitation is not confirmed by the provided source material.

What's Vulnerable

Patch Status

Oracle addressed this vulnerability in its July 2026 Critical Patch Update. Organizations running affected versions (17.0–26.3) should apply the fixes referenced in Oracle's Critical Patch Update advisory as soon as possible, prioritizing internet-facing or network-accessible instances given the 9.8 severity.

Sources