PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-47036 Oracle Corporation CVE debrief

A critical vulnerability was discovered in Siebel CRM Development, affecting versions 17.0-26.3. This easily exploitable vulnerability allows unauthenticated attackers with network access via HTTP to compromise Siebel CRM Development, potentially leading to a complete takeover of the system. The vulnerability is located in the Siebel Approval Manager component and has a CVSS 3.1 Base Score of 9.8, indicating a critical severity level. The CVSS Vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, showing high impacts on confidentiality, integrity, and availability. Organizations using Siebel CRM Development versions 17.0-26.3 should prioritize patching this vulnerability to prevent potential system compromise.

Vendor
Oracle Corporation
Product
Siebel CRM Development
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-08-05
Advisory published
2026-07-21
Advisory updated
2026-08-05

Who should care

Organizations using Siebel CRM Development versions 17.0-26.3 should prioritize patching this vulnerability to prevent potential system compromise. This vulnerability affects operators of Siebel CRM Development, platform administrators, vulnerability management teams, and security teams responsible for ensuring the security and integrity of their systems.

Technical summary

The vulnerability is located in the Siebel Approval Manager component of Siebel CRM Development. It has a CVSS 3.1 Base Score of 9.8, indicating a critical severity level. The CVSS Vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, showing high impacts on confidentiality, integrity, and availability. The vulnerability allows unauthenticated attackers with network access via HTTP to compromise Siebel CRM Development, potentially leading to a complete takeover of the system.

Defensive priority

High

Recommended defensive actions

  • Apply the latest security patches for Siebel CRM Development
  • Restrict network access to Siebel CRM Development
  • Monitor system logs for suspicious activity
  • Consider implementing additional security controls, such as Web Application Firewalls
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record was published on 2026-07-21T22:17:09.170Z and last modified on 2026-07-25T05:16:34.993Z. The NVD entry is currently Awaiting Analysis. This vulnerability affects Siebel CRM Development versions 17.0-26.3, and its severity is critical with a CVSS 3.1 Base Score of 9.8. The CVE record provides limited information, and defenders should verify the affected scope and vendor guidance.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-47036 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-47036

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-47036 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-47036

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.