CVE-2026-47016
Received Received - Intake

Physical Access Unauthorized Data Read in Siebel CRM Integration

Vulnerability report for CVE-2026-47016, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-21

Last updated on: 2026-07-21

Assigner: Oracle

Description

Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Event Publish and Subscribe). Supported versions that are affected are 17.0-26.4. Difficult to exploit vulnerability allows physical access to compromise Siebel CRM Integration. While the vulnerability is in Siebel CRM Integration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Siebel CRM Integration accessible data. CVSS 3.1 Base Score 1.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-21
Last Modified
2026-07-21
Generated
2026-07-22
AI Q&A
2026-07-22
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
oracle siebel_crm_integration From 17.0 (inc) to 26.4 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a physical access vulnerability in Oracle Siebel CRM Integration versions 17.0 to 26.4. It allows an attacker with physical access to read a subset of data from the Siebel CRM Integration system. The impact is limited to confidentiality breaches with no integrity or availability impact.

Detection Guidance

This vulnerability requires physical access to exploit, so detection primarily involves monitoring for unauthorized physical access to systems running Oracle Siebel CRM Integration versions 17.0-26.4. No specific network or system commands are provided in the context.

Impact Analysis

If you have Oracle Siebel CRM Integration installed and physical access is not properly controlled, an attacker could gain unauthorized read access to some of your Siebel CRM data. The impact is low due to the difficulty of exploitation and limited data exposure.

Compliance Impact

This vulnerability could potentially lead to unauthorized data access, which may violate compliance requirements for data protection standards like GDPR or HIPAA if sensitive data is exposed. However, the limited scope and difficulty of exploitation reduce the risk.

Mitigation Strategies

Restrict physical access to systems running Oracle Siebel CRM Integration versions 17.0-26.4. Ensure only authorized personnel can access these systems. Update to a patched version if available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-47016. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart