ZeroHour

CVE-2026-83085

moderate

Adjacent-Network Flaw in Oracle Siebel Cloud Manager Exposes All CRM Data (CVSS 8.2)

CVSS 3.1
8.2 high
EPSS
Published
()
Modified
AI analysis

A high-severity vulnerability (CVSS 3.1: 8.2) exists in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications, affecting versions 22.3 through 26.7. It is described as easily exploitable by a low-privileged attacker who already has access to the physical communication segment (local/adjacent network) attached to the hardware where the Siebel CRM Cloud Applications run — meaning it is not remotely exploitable from the open internet but is reachable by anyone on the same network segment, such as a compromised internal host or low-privileged insider. A successful attack can result in unauthorized access to critical data or complete read access to all data accessible to the application, unauthorized update, insert or delete access to some of that data, and a partial denial of service; the scope is changed (S:C), so successful attacks may also significantly impact additional products beyond Siebel CRM Cloud Applications. Organizations running affected Siebel CRM Cloud Applications deployments should treat this as a serious insider/adjacent-network threat. There is no known public proof of concept and no confirmed in-the-wild exploitation, and the CVE is not on CISA's Known Exploited Vulnerabilities catalog.

What to do: Apply Oracle's Critical Patch Update that remediates this flaw if you run Siebel CRM Cloud Applications versions 22.3-26.7, prioritizing any environment whose Siebel Cloud Manager hosts sit on broadly shared network segments. Because exploitation requires a low-privileged foothold on the adjacent network segment, tighten network segmentation and access controls around the Siebel Cloud Manager infrastructure and audit low-privileged accounts and lateral-movement activity on those segments. Review logs for unexpected bulk data reads, unauthorized inserts/updates/deletes, or partial service disruption traceable to adjacent-network sources.

Affected
Oracle Siebel CRM Cloud Applications (component: Siebel Cloud Manager)22.3-26.7
Estimated exposure
moderatelikely low-thousands of enterprise deployments (exact count not disclosed by Oracle) — Oracle does not publish deployment figures, but Siebel CRM is a legacy enterprise CRM platform with an estimated few thousand organizational customers worldwide, each typically running a small number of cloud environments via Siebel Cloud…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.7. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications. While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data as well as unauthorized update, insert or delete access to some of Siebel CRM Cloud Applications accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L).

Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L

In the news

No ingested article mentions this CVE yet.