ZeroHour

CVE-2026-83143

niche

Unauthenticated Data Manipulation via HTTP in Oracle Siebel Life Sciences eDetailing

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83143 is a high-severity (CVSS 3.1: 8.1) vulnerability in the eDetailing component of Siebel Apps – Life Sciences, part of Oracle Siebel CRM, affecting versions 17.0 through 26.7. An unauthenticated attacker with network access over HTTP can exploit the flaw, but a successful attack requires a human victim to interact with attacker-crafted content (per the UI:R vector), which typically points to a CSRF or similar interaction-dependent attack. If successful, the attacker gains unauthorized ability to create, delete, or modify critical data as well as read access to some or all Siebel Apps – Life Sciences data, with high confidentiality and integrity impact and no availability impact. Organizations running affected Siebel CRM Life Sciences deployments exposed over HTTP are at risk. No public proof-of-concept exists and no exploitation in the wild has been reported; the flaw is not on the CISA Known Exploited Vulnerabilities list.

What to do: Apply the Oracle Critical Patch Update (CPU) that delivers the fix for CVE-2026-83143 and upgrade affected Siebel Apps – Life Sciences deployments from the 17.0–26.7 range to a patched release. In the interim, remove direct HTTP exposure of the eDetailing application (VPN, IP allowlisting, reverse proxy with SSO/MFA) and reinforce anti-CSRF/session hygiene plus user awareness of social-engineering lures that trigger the required victim interaction. Review audit logs for unexpected data creation, modification, or deletion in Life Sciences records.

Affected
Oracle Siebel Apps – Life Sciences (Siebel CRM, component: eDetailing)17.0-26.7
Estimated exposure
nichelikely hundreds of enterprise deployments worldwide (low thousands of Siebel CRM instances overall, with Life Sciences eDetailing a specialized pharma subset) — Siebel CRM is a legacy enterprise platform concentrated in large regulated organizations, the Life Sciences eDetailing module serves a narrow pharma market, and internet-wide scans typically show only low thousands of exposed Siebel…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel Apps - Life Sciences product of Oracle Siebel CRM (component: eDetailing). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Life Sciences. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel Apps - Life Sciences accessible data as well as unauthorized access to critical data or complete access to all Siebel Apps - Life Sciences accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.