ZeroHour

CVE-2026-83183

moderate

Unauthenticated HTTP Denial-of-Service in Oracle Siebel CRM Deployment

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83183 is an easily exploitable denial-of-service flaw in the Server Infrastructure component of Oracle Siebel CRM's Deployment functionality, affecting supported versions 17.0 through 26.7. An unauthenticated remote attacker with network access via HTTP can send crafted requests that cause the Siebel CRM Deployment service to hang or crash in a repeatable manner, resulting in complete denial of service. The vulnerability affects availability only — confidentiality and integrity are not impacted, per the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, score 7.5). Organizations running on-premises Siebel CRM deployments with the Deployment/Server Infrastructure component reachable over HTTP are the primary concern, especially if the service is internet-facing. The issue is not on the CISA KEV list and no public proof-of-concept or observed in-the-wild exploitation is known at this time.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83183 to all Siebel CRM installations running versions 17.0 through 26.7. Restrict network access to Siebel Deployment/Server Infrastructure HTTP endpoints so they are reachable only from trusted administrative networks, and avoid exposing them to the internet. Monitor Siebel Deployment services for unexpected hangs or repeatable crashes, which would indicate attempted exploitation.

Affected
Oracle Siebel CRM (Deployment component: Server Infrastructure)17.0 - 26.7 (all supported versions in this range)
Estimated exposure
moderatelikely low thousands of enterprise deployments, with only a subset (hundreds to low thousands) internet-exposed — Siebel CRM is legacy on-premises enterprise software concentrated at large organizations, with total global installations commonly estimated in the low thousands and public internet scans typically showing only a fraction of those servers…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Deployment. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

Weakness
CWE-400
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.