CVE-2026-47016

LOW

Siebel CRM Integration 17.0-26.4 - Unauthorized Data Access via Physical Access to Event Publish and Subscribe Component

Title source: llm
STIX 2.1

Description

Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Event Publish and Subscribe). Supported versions that are affected are 17.0-26.4. Difficult to exploit vulnerability allows physical access to compromise Siebel CRM Integration. While the vulnerability is in Siebel CRM Integration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Siebel CRM Integration accessible data. CVSS 3.1 Base Score 1.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N).

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory
Oracle Advisory
https://www.oracle.com/security-alerts/cpujul2026.html

Scores

CVSS v3 1.9
EPSS 0.0012
EPSS Percentile 1.9%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
Oracle Corporation/Siebel CRM Integration 17.0 - 26.4
Published Jul 21, 2026
Tracked Since Jul 22, 2026