Impact
The vulnerability resides in the Server Infrastructure component of Oracle Siebel CRM Deployment. An attacker who can logon locally with low privileges can exploit this weakness to take over the deployment. The flaw, characterized as an improper access control issue (CWE-269), leads to full confidentiality, integrity, and availability loss once compromised.
Affected Systems
Oracle Corporation’s Siebel CRM Deployment product is impacted. Versions from 17.0 through 26.7 contain the flaw. Any environment running these products without the vendor‑issued fix is vulnerable.
Risk and Exploitability
The CVSS v3.1 base score of 7.8 reflects significant risk. The EPSS score is below 1%, indicating a low but non‑zero likelihood of exploitation in the wild, and the vulnerability is not currently listed in CISA KEV. Local attackers with logon rights who can execute code on the infrastructure are the primary threat vector, and they can achieve full control of the deployment with no user interaction.
OpenCVE Enrichment