ZeroHour

CVE-2026-73966

moderate

Privileged Remote Takeover Flaw in Oracle Siebel Apps – Marketing (CVE-2026-73966)

CVSS 3.1
7.2 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-73966 is a vulnerability in the Marketing component of Oracle Siebel Apps within Oracle Siebel CRM, affecting supported versions 17.0 through 26.7. Oracle rates it as easily exploitable by a remote attacker with network access via HTTP who already holds high privileges, meaning an authenticated, admin-level user can trigger the flaw through normal web interactions with the Marketing module. A successful attack results in complete takeover of Siebel Apps – Marketing, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.2). Organizations running Siebel CRM with the Marketing application exposed to broad internal or external networks are the primary concern, since the flaw is contained to that component (scope unchanged). There is no known public proof of concept and the CVE is not on the CISA Known Exploited Vulnerabilities list, so exploitation status is none known.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-73966 to all Siebel CRM deployments in the 17.0–26.7 range running the Marketing application. Because exploitation requires a high-privilege account, audit and least-privilege administrative roles, enforce MFA, and monitor privileged accounts for anomalous activity against Marketing URLs. Restrict HTTP access to the Siebel Marketing module to trusted networks and management segments where possible.

Affected
Oracle Siebel CRM (Siebel Apps – Marketing, component: Marketing)17.0-26.7
Estimated exposure
moderate≈1,000–10,000 installations, likely on the lower end (thousands of internet-reachable Siebel endpoints, with only a subset licensed for Marketing) — Estimate based on the typical number of internet-exposed Siebel web server (SWSE) endpoints seen in public internet-wide scans and Siebel's deployment base of large enterprises; the fraction running the Marketing module is unknown.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this vulnerability can result in takeover of Siebel Apps - Marketing. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.