CVE-2026-83079
nichePrivilege Escalation in Oracle Siebel Cloud Manager Exposes Full CRM Data
CVE-2026-83079 is a high-severity (CVSS 7.9) flaw in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications, affecting supported versions 22.3 through 26.7. It is easily exploitable by an attacker who already holds high privileges and has logged on to the infrastructure where the Siebel cloud deployment executes, i.e., a local attack path rather than a remote one. Because the vulnerability changes scope, a successful attack can impact products beyond Siebel itself and grants unauthorized creation, deletion, or modification of critical data, plus full read access to all data accessible through Siebel CRM Cloud Applications (high confidentiality and integrity impact, no availability impact). Affected organizations are enterprises running Oracle Siebel CRM in the cloud under the listed versions, particularly those with broad or poorly monitored privileged access on hosting infrastructure. There is no known public PoC, it is not on the CISA KEV list, and no exploitation in the wild has been reported.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83079 to all Siebel CRM Cloud Applications deployments in the 22.3-26.7 range. Enforce least-privilege and MFA for accounts with logon access to the infrastructure hosting Siebel Cloud Manager, and audit those accounts for anomalous activity. Review Siebel-accessible data for unauthorized creation, deletion, or modification, and rotate credentials for privileged infrastructure accounts if compromise is suspected.
| Oracle Siebel CRM Cloud Applications (Siebel Cloud Manager component) | 22.3-26.7 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.7. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications. While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Cloud Applications accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 7.9 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N).
- Vector
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.