Vulnerability in Oracle Siebel CRM Integration Affects Critical Data Access
CVE-2026-47016

1.9LOW

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-47016?

A significant access control vulnerability exists in the Event Publish and Subscribe component of Oracle's Siebel CRM Integration. This flaw, found in versions 17.0 to 26.4, enables potential attackers with physical access to the system to exploit the vulnerability, leading to unauthorized read access to certain sensitive data within the Siebel CRM Integration. While the core of the vulnerability impacts this specific component, the repercussions may extend to additional Oracle products, heightening the severity of potential data breaches. Organizations using affected versions are advised to assess their security posture and apply necessary updates to mitigate risks.

Affected Version(s)

Siebel CRM Integration 17.0 <= 26.4

References

CVSS V3.1

Score:
1.9
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.