A critical, easily exploitable vulnerability in Oracle Siebel CRM Development allows an unauthenticated remote attacker to fully compromise the affected system over HTTP.
What Is It
CVE-2026-47036 is a critical vulnerability in the Siebel CRM Development product of Oracle Siebel CRM, specifically within the Siebel Approval Manager component. According to Oracle's advisory, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via HTTP to compromise Siebel CRM Development. Successful exploitation can result in complete takeover of Siebel CRM Development.
It carries a CVSS 3.1 Base Score of 9.8 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, meaning network attack vector, low complexity, no privileges or user interaction required, and high impact to confidentiality, integrity, and availability.
Why It Matters
The combination of no authentication, no user interaction, low attack complexity, and full compromise makes this among the most severe classes of vulnerability. A successful attack yields takeover of the affected CRM environment, exposing sensitive business and customer data as well as the integrity and availability of the system. Because exploitation requires only HTTP network access, any internet-reachable or otherwise accessible instance is at high risk.
Note: No CISA KEV entry was supplied for this CVE, so active exploitation is not confirmed by the provided source material.
What's Vulnerable
- Product: Oracle Siebel CRM, Siebel CRM Development
- Component: Siebel Approval Manager
- Affected versions: 17.0 through 26.3 (supported versions)
- Vendor: Oracle Corporation
Patch Status
Oracle addressed this vulnerability in its July 2026 Critical Patch Update. Organizations running affected versions (17.0–26.3) should apply the fixes referenced in Oracle's Critical Patch Update advisory as soon as possible, prioritizing internet-facing or network-accessible instances given the 9.8 severity.
Sources
- Oracle Critical Patch Update Advisory; July 2026: https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-47036: https://nvd.nist.gov/vuln/detail/CVE-2026-47036