CVE-2026-83087
moderateLow-Privilege Data Takeover in Oracle Siebel CRM Cloud Manager (versions 22.3–26.7)
CVE-2026-83087 is a difficult-to-exploit vulnerability in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications, affecting releases 22.3 through 26.7. A remote attacker who already holds low-privilege credentials and has HTTP network access to the product can trigger the flaw and compromise Siebel CRM Cloud Applications. Because the vulnerability carries a scope change, successful attacks can also significantly impact additional products beyond Siebel itself. The impact is unauthorized creation, deletion, or modification of critical data (or all Siebel-accessible data), as well as unauthorized read access to critical data or complete access to all accessible data, reflected in a CVSS 3.1 base score of 8.2 (AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N). No public proof of concept exists, the flaw is not on the CISA KEV list, and no exploitation in the wild has been reported.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83087 to all Siebel CRM Cloud Applications instances running versions 22.3 through 26.7. Restrict HTTP access to Siebel Cloud Manager to trusted networks and strictly enforce least-privilege roles for low-privileged accounts, since exploitation requires valid low-privilege credentials. Review audit logs for anomalous data access, creation, or modification by low-privilege users, and check whether other products in the environment were touched given the scope-change impact.
| Oracle Siebel CRM Cloud Applications (component: Siebel Cloud Manager) | 22.3-26.7 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.7. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Cloud Applications accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.