ZeroHour

CVE-2026-83086

niche

Low-Privilege Account Takeover Flaw in Oracle Siebel CRM Cloud Manager

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

A high-severity vulnerability (CVSS 3.1 base score 8.8) in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications allows a low-privileged attacker with network access via HTTP to compromise the affected Siebel deployment. The flaw is rated easily exploitable: it requires only an authenticated low-privilege account, no user interaction, and no special conditions. Successful attacks can result in complete takeover of Siebel CRM Cloud Applications with high impact on confidentiality, integrity, and availability. All supported releases from 22.3 through 26.7 are affected. No public proof of concept exists, the issue is not on CISA's Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation is known.

What to do: Apply the Oracle Critical Patch Update addressing this CVE as soon as it is available and move Siebel Cloud Manager to a patched build or a release later than 26.7. Restrict HTTP/network access to the Cloud Manager interface to trusted administrative networks, and enforce least-privilege and strong authentication on all Siebel accounts since exploitation starts from a low-privileged login. Review audit logs for anomalous activity by low-privileged accounts against Cloud Manager endpoints.

Affected
Oracle Siebel CRM Cloud Applications (component: Siebel Cloud Manager)22.3-26.7
Estimated exposure
nichelikely hundreds to low thousands of enterprise deployments; exact count unknown — Siebel CRM is an enterprise-only product with a limited customer base, and the vulnerable Siebel Cloud Manager component applies specifically to Oracle Cloud-hosted Siebel deployments; no public install counts or scan data are available.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.