CVE-2026-83183
moderateUnauthenticated HTTP Denial-of-Service in Oracle Siebel CRM Deployment
CVE-2026-83183 is an easily exploitable denial-of-service flaw in the Server Infrastructure component of Oracle Siebel CRM's Deployment functionality, affecting supported versions 17.0 through 26.7. An unauthenticated remote attacker with network access via HTTP can send crafted requests that cause the Siebel CRM Deployment service to hang or crash in a repeatable manner, resulting in complete denial of service. The vulnerability affects availability only — confidentiality and integrity are not impacted, per the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, score 7.5). Organizations running on-premises Siebel CRM deployments with the Deployment/Server Infrastructure component reachable over HTTP are the primary concern, especially if the service is internet-facing. The issue is not on the CISA KEV list and no public proof-of-concept or observed in-the-wild exploitation is known at this time.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83183 to all Siebel CRM installations running versions 17.0 through 26.7. Restrict network access to Siebel Deployment/Server Infrastructure HTTP endpoints so they are reachable only from trusted administrative networks, and avoid exposing them to the internet. Monitor Siebel Deployment services for unexpected hangs or repeatable crashes, which would indicate attempted exploitation.
| Oracle Siebel CRM (Deployment component: Server Infrastructure) | 17.0 - 26.7 (all supported versions in this range) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Deployment. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
- Weakness
- CWE-400
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.