PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-47036 Oracle Corporation CVE debrief

A critical vulnerability was discovered in Siebel CRM Development, affecting versions 17.0-26.3. This easily exploitable vulnerability allows unauthenticated attackers with network access via HTTP to compromise Siebel CRM Development, potentially leading to a complete takeover of the system. The vulnerability is located in the Siebel Approval Manager component and has a CVSS 3.1 Base Score of 9.8, indicating a critical severity level. The CVSS Vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, showing high impacts on confidentiality, integrity, and availability. Organizations using Siebel CRM Development versions 17.0-26.3 should prioritize patching this vulnerability to prevent potential system compromise.

Vendor
Oracle Corporation
Product
Siebel CRM Development
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-25
Advisory published
2026-07-21
Advisory updated
2026-07-25

Who should care

Organizations using Siebel CRM Development versions 17.0-26.3 should prioritize patching this vulnerability to prevent potential system compromise. This vulnerability affects operators of Siebel CRM Development, platform administrators, vulnerability management teams, and security teams responsible for ensuring the security and integrity of their systems.

Technical summary

The vulnerability is located in the Siebel Approval Manager component of Siebel CRM Development. It has a CVSS 3.1 Base Score of 9.8, indicating a critical severity level. The CVSS Vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, showing high impacts on confidentiality, integrity, and availability. The vulnerability allows unauthenticated attackers with network access via HTTP to compromise Siebel CRM Development, potentially leading to a complete takeover of the system.

Defensive priority

High

Recommended defensive actions

  • Apply the latest security patches for Siebel CRM Development
  • Restrict network access to Siebel CRM Development
  • Monitor system logs for suspicious activity
  • Consider implementing additional security controls, such as Web Application Firewalls
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record was published on 2026-07-21T22:17:09.170Z and last modified on 2026-07-25T05:16:34.993Z. The NVD entry is currently Awaiting Analysis. This vulnerability affects Siebel CRM Development versions 17.0-26.3, and its severity is critical with a CVSS 3.1 Base Score of 9.8. The CVE record provides limited information, and defenders should verify the affected scope and vendor guidance.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:09.170Z and has not been modified since then. The NVD entry is currently Awaiting Analysis.