ZeroHour

CVE-2026-83144

moderate

User-Interaction Data Access Flaw in Oracle Siebel CRM Order Management (CVSS 8.7)

CVSS 3.1
8.7 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83144 is a high-severity vulnerability in the Customer Order Management product of Oracle Siebel CRM (Order Management component), affecting all supported versions from 17.0 through 26.7. A low-privileged attacker with network access via HTTP can exploit the flaw easily, but successful attacks require a human victim to interact with attacker-controlled content — a pattern consistent with CSRF/client-side attack techniques — and the impact can extend beyond Order Management to additional products (scope change). A successful attack gives the attacker unauthorized ability to create, delete, or modify critical data, as well as unauthorized access to all data accessible through Siebel Apps - Customer Order Management, with high impacts on both confidentiality and integrity (no availability impact). The flaw is fixed in Oracle's Critical Patch Update corresponding to version 26.7 or later, and no public proof-of-concept or observed in-the-wild exploitation is known at this time.

What to do: Apply the Oracle Critical Patch Update that remediates this issue (upgrade to a Siebel CRM release/CPU beyond the affected 17.0-26.7 range). Because exploitation requires user interaction, enforce SameSite cookie attributes and short session timeouts on Siebel web clients, train order-management users against phishing/lure-driven interaction, and audit low-privileged accounts for anomalous data creation, modification, or access in Order Management records.

Affected
Oracle Siebel Apps - Customer Order Management (Oracle Siebel CRM, component: Order Management)17.0 - 26.7 (all supported versions in this range)
Estimated exposure
moderateLikely low thousands of enterprise deployments worldwide (thousands to hundreds of thousands of end users), with a smaller subset internet-exposed — Siebel CRM is a legacy enterprise suite concentrated in large organizations with declining but still substantial market share, typically deployed internally or behind VPN, so only a fraction of instances are directly internet-reachable.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel Apps - Customer Order Management product of Oracle Siebel CRM (component: Order Management). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps - Customer Order Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel Apps - Customer Order Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel Apps - Customer Order Management accessible data as well as unauthorized access to critical data or complete access to all Siebel Apps - Customer Order Management accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.