ZeroHour

CVE-2026-83153

moderate

Low-Privilege Takeover Flaw in Oracle Siebel CRM Deployment (17.0-26.7)

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83153 is a high-severity vulnerability in the Server Infrastructure component of Oracle Siebel CRM Deployment, affecting all supported versions from 17.0 through 26.7. It is easily exploitable by a low-privileged (authenticated) attacker with network access via HTTPS, requiring no user interaction. A successful attack allows the attacker to fully compromise the Siebel CRM Deployment, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 8.8). Organizations running affected Siebel CRM versions exposed to authenticated users over network connections are at risk. There is no known public proof of concept and no evidence of in-the-wild exploitation, and the flaw is not on the CISA KEV list.

What to do: Apply the Oracle Critical Patch Update that remediates this issue and move to the first patched release above 26.7 as soon as it is available. Until patched, restrict HTTPS access to Siebel CRM Deployment so only trusted authenticated users and networks can reach the Server Infrastructure component, and audit low-privileged accounts for suspicious activity. Review server logs for anomalous privileged actions originating from standard user accounts.

Affected
Oracle Siebel CRM (Siebel CRM Deployment, Server Infrastructure component)17.0 - 26.7
Estimated exposure
moderatelikely a few thousand enterprise deployments worldwide, with only a fraction internet-exposed — Siebel CRM is an on-premises enterprise suite typically deployed inside corporate perimeters for large organizations, so the deployment base is far smaller than cloud CRM products and public scan surfaces are limited; this is an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.