ZeroHour

CVE-2026-83182

moderate

Low-Privilege SQL Injection Allows Takeover in Oracle Siebel CRM Configuration Tools

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

A difficult-to-exploit SQL injection flaw in the Configuration Tools component of Oracle Siebel CRM (Development installations) lets a low-privileged attacker with network access send malicious SQL and compromise the Siebel CRM Development environment. Successful attacks result in full impact to confidentiality, integrity, and availability — effectively a complete takeover of the affected development environment. All supported versions from 17.0 through 26.7 are affected. Exploitation requires an authenticated low-privilege account and is rated as having high attack complexity, and there is no public proof-of-concept or known in-the-wild exploitation to date. Oracle addressed the flaw via its Critical Patch Update process (CNA: [email protected]), and it is not on the CISA Known Exploited Vulnerabilities catalog.

What to do: Apply the Oracle Critical Patch Update that remediates this issue to all supported Siebel CRM installations (versions 17.0 through 26.7). Restrict network access to Siebel Development and Configuration Tools environments to trusted administrators and VPN ranges, and enforce least-privilege database credentials for application users. Audit low-privileged accounts for unusual SQL activity indicative of injection attempts.

Affected
Oracle Siebel CRM (Development, component: Configuration Tools)17.0 - 26.7 (supported versions)
Estimated exposure
moderate≈ low thousands of enterprise Siebel deployments; Development/Configuration Tools instances typically internal-facing — Siebel CRM is a legacy on-premises enterprise CRM with an install base typically measured in thousands of organizations rather than millions of hosts, and no public scan data exists for internet-exposed Configuration Tools endpoints.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Configuration Tools). Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability allows low privileged attacker with network access via SQL to compromise Siebel CRM Development. Successful attacks of this vulnerability can result in takeover of Siebel CRM Development. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.