CVE-2026-83145
moderatePrivileged CSRF-Style Data Manipulation in Oracle Siebel CRM Customer Order Management
CVE-2026-83145 is a high-severity flaw (CVSS 3.1: 8.7) in the Order Management component of Oracle Siebel CRM's Customer Order Management application, affecting versions 17.0 through 26.7. It is easily exploitable over HTTP by a low-privileged (authenticated) attacker, but requires interaction from a victim user other than the attacker — a pattern consistent with cross-site request forgery or similar session-riding techniques. A successful attack allows unauthorized creation, deletion, or modification of critical order-management data, as well as unauthorized read access to all data accessible through the component, and because of a scope change it may also significantly impact additional products beyond Customer Order Management. Any organization running Siebel CRM Order Management in the affected version range is at risk, particularly deployments reachable by low-privilege internal or portal users. No public proof of concept is known and the flaw is not on the CISA KEV list, so exploitation in the wild is presumed unlikely at this time.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83145 to all Siebel CRM installations running versions 17.0-26.7, prioritizing any environment where Customer Order Management is exposed to low-privilege or partner/portal users. In the interim, verify that anti-CSRF protections, session cookies with SameSite attributes, and network segmentation restricting HTTP access to Siebel application servers are in place. Review audit logs for anomalous order creation, deletion, or modification and unexpected data access by low-privileged accounts over the past several months.
| Oracle Siebel Apps - Customer Order Management (Oracle Siebel CRM, component: Order Management) | 17.0-26.7 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Siebel Apps - Customer Order Management product of Oracle Siebel CRM (component: Order Management). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps - Customer Order Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel Apps - Customer Order Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel Apps - Customer Order Management accessible data as well as unauthorized access to critical data or complete access to all Siebel Apps - Customer Order Management accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.