CVE-2026-83074
nicheUnauthenticated SSH Access Flaw in Oracle Siebel Cloud Manager Exposes Critical Data
CVE-2026-83074 is a high-severity (CVSS 3.1: 8.6) vulnerability in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications, affecting releases 22.3 through 26.7. It is easily exploitable by an unauthenticated attacker who has network access to the target via SSH, requiring no privileges or user interaction. A successful attack results in unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data, and because the vulnerability has a scope change, successful attacks may also significantly impact additional products beyond Siebel itself. The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N) indicates a pure confidentiality impact with no direct effect on integrity or availability. The flaw is not in CISA's Known Exploited Vulnerabilities catalog and no public proof-of-concept is known, so exploitation status is currently none known.
What to do: Apply the Oracle Critical Patch Update that remediates this issue, moving off any affected release in the 22.3-26.7 range. Restrict network and SSH access to the Siebel Cloud Manager host (VPN/bastion, strict allowlists, disable direct internet SSH exposure) and enforce strong key-based authentication. Review SSH authentication and session logs for the Cloud Manager system for signs of unauthorized access or anomalous data retrieval.
| Oracle Siebel CRM Cloud Applications (component: Siebel Cloud Manager) | 22.3-26.7 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via SSH to compromise Siebel CRM Cloud Applications. While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.