ZeroHour

CVE-2026-83145

moderate

Privileged CSRF-Style Data Manipulation in Oracle Siebel CRM Customer Order Management

CVSS 3.1
8.7 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83145 is a high-severity flaw (CVSS 3.1: 8.7) in the Order Management component of Oracle Siebel CRM's Customer Order Management application, affecting versions 17.0 through 26.7. It is easily exploitable over HTTP by a low-privileged (authenticated) attacker, but requires interaction from a victim user other than the attacker — a pattern consistent with cross-site request forgery or similar session-riding techniques. A successful attack allows unauthorized creation, deletion, or modification of critical order-management data, as well as unauthorized read access to all data accessible through the component, and because of a scope change it may also significantly impact additional products beyond Customer Order Management. Any organization running Siebel CRM Order Management in the affected version range is at risk, particularly deployments reachable by low-privilege internal or portal users. No public proof of concept is known and the flaw is not on the CISA KEV list, so exploitation in the wild is presumed unlikely at this time.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83145 to all Siebel CRM installations running versions 17.0-26.7, prioritizing any environment where Customer Order Management is exposed to low-privilege or partner/portal users. In the interim, verify that anti-CSRF protections, session cookies with SameSite attributes, and network segmentation restricting HTTP access to Siebel application servers are in place. Review audit logs for anomalous order creation, deletion, or modification and unexpected data access by low-privileged accounts over the past several months.

Affected
Oracle Siebel Apps - Customer Order Management (Oracle Siebel CRM, component: Order Management)17.0-26.7
Estimated exposure
moderatelow thousands of enterprise Siebel deployments worldwide, with only a subset of Order Management modules internet-reachable — Siebel CRM is a legacy large-enterprise application typically deployed on-premises or in private Oracle Cloud tenancies with a shrinking customer base measured in the low thousands of organizations, and public internet scans show limited…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel Apps - Customer Order Management product of Oracle Siebel CRM (component: Order Management). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps - Customer Order Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel Apps - Customer Order Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel Apps - Customer Order Management accessible data as well as unauthorized access to critical data or complete access to all Siebel Apps - Customer Order Management accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.