CVE-2026-83190
moderateLocal Takeover Flaw in Oracle Siebel CRM Deployment Server Infrastructure (17.0-26.7)
CVE-2026-83190 is a vulnerability in the Server Infrastructure component of Oracle Siebel CRM Deployment, affecting all supported releases from 17.0 through 26.7. It is easily exploitable by a low-privileged attacker who already has logon access to the host where Siebel CRM Deployment executes, but a successful attack requires interaction from a person other than the attacker (per the CVSS vector UI:R), suggesting a social-engineering or user-triggered element. If exploited, the attacker can fully compromise the Siebel CRM Deployment, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.3). Because the attack vector is local (AV:L), only organizations running affected Siebel CRM servers and the workstations/users operating them are exposed, not internet-facing passers-by. There is no known public proof-of-concept and the CVE is not on the CISA Known Exploited Vulnerabilities list, so exploitation status is none known.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83190 and upgrade Siebel CRM Deployment to a release newer than 26.7 that contains the fix. Restrict and audit local OS accounts on hosts running Siebel CRM Server Infrastructure, since the flaw requires local logon with low privileges. Because exploitation requires user interaction, brief admins and operators on Siebel hosts against social-engineering attempts, and review those systems for anomalous local account activity or unexpected configuration changes.
| Oracle Siebel CRM (Siebel CRM Deployment, component: Server Infrastructure) | 17.0 through 26.7 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Deployment executes to compromise Siebel CRM Deployment. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.