PatchSiren cyber security CVE debrief
CVE-2026-47036 Oracle Corporation CVE debrief
A critical vulnerability was discovered in Siebel CRM Development, affecting versions 17.0-26.3. This easily exploitable vulnerability allows unauthenticated attackers with network access via HTTP to compromise Siebel CRM Development, potentially leading to a complete takeover of the system. The vulnerability is located in the Siebel Approval Manager component and has a CVSS 3.1 Base Score of 9.8, indicating a critical severity level. The CVSS Vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, showing high impacts on confidentiality, integrity, and availability. Organizations using Siebel CRM Development versions 17.0-26.3 should prioritize patching this vulnerability to prevent potential system compromise.
- Vendor
- Oracle Corporation
- Product
- Siebel CRM Development
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-25
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-25
Who should care
Organizations using Siebel CRM Development versions 17.0-26.3 should prioritize patching this vulnerability to prevent potential system compromise. This vulnerability affects operators of Siebel CRM Development, platform administrators, vulnerability management teams, and security teams responsible for ensuring the security and integrity of their systems.
Technical summary
The vulnerability is located in the Siebel Approval Manager component of Siebel CRM Development. It has a CVSS 3.1 Base Score of 9.8, indicating a critical severity level. The CVSS Vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, showing high impacts on confidentiality, integrity, and availability. The vulnerability allows unauthenticated attackers with network access via HTTP to compromise Siebel CRM Development, potentially leading to a complete takeover of the system.
Defensive priority
High
Recommended defensive actions
- Apply the latest security patches for Siebel CRM Development
- Restrict network access to Siebel CRM Development
- Monitor system logs for suspicious activity
- Consider implementing additional security controls, such as Web Application Firewalls
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record was published on 2026-07-21T22:17:09.170Z and last modified on 2026-07-25T05:16:34.993Z. The NVD entry is currently Awaiting Analysis. This vulnerability affects Siebel CRM Development versions 17.0-26.3, and its severity is critical with a CVSS 3.1 Base Score of 9.8. The CVE record provides limited information, and defenders should verify the affected scope and vendor guidance.
Official resources
-
CVE-2026-47036 CVE record
CVE.org
-
CVE-2026-47036 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:09.170Z and has not been modified since then. The NVD entry is currently Awaiting Analysis.