CVE-2026-83075
moderateUnauthenticated Critical Data Disclosure in Oracle Siebel CRM Cloud Manager (CVE-2026-83075)
CVE-2026-83075 is an easily exploitable flaw in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications, affecting supported versions 22.3 through 26.7. An unauthenticated attacker with network access over HTTP can exploit the flaw without any user interaction or credentials, and successful attacks result in unauthorized access to critical data or complete read access to all Siebel CRM Cloud Applications data. The impact is confidentiality-only (CVSS 3.1 base score 7.5, vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), meaning data theft is possible but no modification or disruption of service. Organizations running Siebel CRM Cloud Applications releases 22.3-26.7 are affected. No public proof-of-concept exists, the flaw is not on the CISA Known Exploited Vulnerabilities list, and no exploitation in the wild has been reported to date.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83075 and move Siebel CRM Cloud Applications to the fixed release at or beyond 26.7. Restrict network access to Siebel Cloud Manager HTTP endpoints to trusted sources or management networks until patched. Review access and data-export logs for unauthenticated HTTP activity against Cloud Manager to rule out pre-patch data exposure.
| Oracle Siebel CRM Cloud Applications (component: Siebel Cloud Manager) | 22.3 - 26.7 (all supported versions in this range) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.