ZeroHour

CVE-2026-82992

moderate

Local Privilege Escalation to Full Takeover in Oracle Siebel CRM Deployment (17.0-26.7)

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-82992 is a local privilege escalation flaw in the Installation component of Oracle Siebel CRM Deployment, affecting supported versions 17.0 through 26.7. It is easily exploitable by a low-privileged attacker who already has logon access to the server or infrastructure where Siebel CRM Deployment executes, requiring no user interaction. A successful attack allows the attacker to fully compromise the Siebel CRM Deployment, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.8). Organizations running Siebel CRM Deployment on shared or multi-tenant hosts where untrusted or low-privilege accounts exist are most at risk, since the flaw requires local access rather than network reachability. There is no evidence of exploitation in the wild, the CVE is not on the CISA KEV list, and no public proof-of-concept is known.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-82992 to all Siebel CRM Deployment installations running versions 17.0-26.7. Restrict interactive and service-account logon on Siebel servers to trusted administrators only, and audit local OS accounts and privilege escalation activity on those hosts. Since exploitation requires local access, prioritize hosts where Siebel shares infrastructure with less-trusted workloads or users.

Affected
Oracle Siebel CRM Deployment (component: Installation)17.0 through 26.7 (all supported versions in this range)
Estimated exposure
moderate≈1,000-10,000 enterprise Siebel CRM deployments (estimated) — Siebel CRM is on-premises/enterprise software deployed at a few thousand large organizations worldwide, but Oracle publishes no install counts and the local attack vector means exposure is limited to deployments where untrusted users can…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Installation). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Deployment executes to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.