ZeroHour

CVE-2026-83180

moderate

Authenticated Takeover Flaw in Oracle Siebel CRM Deployment Server Infrastructure

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

Oracle Siebel CRM contains a high-severity (CVSS 8.8) vulnerability in the Siebel CRM Deployment component, specifically in Server Infrastructure, affecting versions 17.0 through 26.7. A low-privileged attacker with network access via HTTP can exploit this flaw — described by Oracle as easily exploitable — without any user interaction to fully compromise the Siebel CRM Deployment. A successful attack results in a complete takeover, with high impact on confidentiality, integrity, and availability of the affected deployment. In practice, this means any authenticated low-level user (such as a standard CRM end user with a reachable HTTP endpoint) could pivot to control of the deployment. No public proof of concept is known and the vulnerability is not on CISA's KEV list, so there is no evidence of active exploitation to date.

What to do: Apply the Oracle Critical Patch Update that remediates this issue, prioritizing any Siebel CRM Deployment instances running versions 17.0 through 26.7. Restrict HTTP access to Siebel server infrastructure so only trusted networks and authenticated users can reach it, and audit low-privileged accounts for suspicious privilege escalation or unauthorized administrative activity.

Affected
Oracle Siebel CRM (Siebel CRM Deployment, component: Server Infrastructure)17.0-26.7
Estimated exposure
moderate≈ thousands of enterprise deployments, with low thousands of internet-exposed Siebel endpoints — Siebel is an on-premises enterprise CRM deployed primarily by large organizations worldwide (typically a few thousand enterprise customers), and public internet scan data has historically shown only low thousands of exposed Siebel web…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.