CVE-2026-83073
nicheUnauthenticated Adjacent-Network Data Access in Oracle Siebel Cloud Manager (22.3-26.7)
CVE-2026-83073 is an easily exploitable flaw in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications, affecting releases 22.3 through 26.7. It allows an unauthenticated attacker who can reach the network segment attached to the hardware where the Siebel CRM Cloud Applications run (adjacent-network access, CVSS 3.1: 8.1) to compromise the application. A successful attack yields unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to critical data or all data accessible through Siebel CRM Cloud Applications; availability is not impacted. Exploitation requires proximity to the internal or cloud network segment rather than exposure to the open internet, which limits the attacker pool but not the severity for reachable deployments. No public proof-of-concept exists and the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog, so no active exploitation is currently known.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83073 to all Siebel CRM Cloud Applications deployments running releases 22.3-26.7, prioritizing the Siebel Cloud Manager component. Enforce strict network segmentation so that only trusted administrative hosts can reach the communication segment where Siebel CRM Cloud Applications executes, and verify cloud VCN/firewall rules accordingly. Review audit logs for unauthenticated data creation, modification, or deletion and rotate relevant credentials if suspicious activity is found.
| Oracle Siebel CRM Cloud Applications (component: Siebel Cloud Manager) | 22.3-26.7 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.7. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Cloud Applications accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
- Vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.