ZeroHour

CVE-2026-83074

niche

Unauthenticated SSH Access Flaw in Oracle Siebel Cloud Manager Exposes Critical Data

CVSS 3.1
8.6 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83074 is a high-severity (CVSS 3.1: 8.6) vulnerability in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications, affecting releases 22.3 through 26.7. It is easily exploitable by an unauthenticated attacker who has network access to the target via SSH, requiring no privileges or user interaction. A successful attack results in unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data, and because the vulnerability has a scope change, successful attacks may also significantly impact additional products beyond Siebel itself. The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N) indicates a pure confidentiality impact with no direct effect on integrity or availability. The flaw is not in CISA's Known Exploited Vulnerabilities catalog and no public proof-of-concept is known, so exploitation status is currently none known.

What to do: Apply the Oracle Critical Patch Update that remediates this issue, moving off any affected release in the 22.3-26.7 range. Restrict network and SSH access to the Siebel Cloud Manager host (VPN/bastion, strict allowlists, disable direct internet SSH exposure) and enforce strong key-based authentication. Review SSH authentication and session logs for the Cloud Manager system for signs of unauthorized access or anomalous data retrieval.

Affected
Oracle Siebel CRM Cloud Applications (component: Siebel Cloud Manager)22.3-26.7
Estimated exposure
nichelikely hundreds to low thousands of enterprise cloud deployments — Oracle Siebel CRM is enterprise software with a limited (though high-value) customer base, and only cloud deployments using the Siebel Cloud Manager component with network-reachable SSH are exposed; no public install counts or scan data…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via SSH to compromise Siebel CRM Cloud Applications. While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.