ZeroHour

CVE-2026-83191

moderate

Unauthenticated Takeover Flaw in Oracle Siebel CRM Deployment (17.0-26.7)

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83191 is a difficult-to-exploit, unauthenticated vulnerability in the Server Infrastructure component of the Siebel CRM Deployment product in Oracle Siebel CRM, affecting supported versions 17.0 through 26.7. An unauthenticated attacker who can reach the Siebel CRM Deployment server over the network via TCP could exploit the flaw, and a successful attack results in a complete takeover of the Siebel CRM Deployment, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 8.1). Exploitation requires no privileges and no user interaction, but the high attack complexity means an attacker would need to overcome significant conditions, such as timing or race conditions, limiting opportunistic abuse. Organizations running affected Siebel CRM versions are exposed wherever the server infrastructure is reachable over TCP, particularly if ports are exposed beyond trusted internal networks. There is no known public proof of concept and the vulnerability is not on the CISA Known Exploited Vulnerabilities catalog, so exploitation in the wild appears unlikely at this time.

What to do: Apply the Oracle Critical Patch Update that remediates this flaw to move off affected versions 17.0-26.7 of Siebel CRM Deployment. Restrict TCP access to Siebel server infrastructure ports to trusted hosts and VPN ranges via firewall allowlists, since the attack requires network reachability. Review logs for unexpected unauthenticated TCP connections to Siebel Deployment servers and verify the integrity of deployment configurations as a post-remediation check.

Affected
Oracle Siebel CRM (Siebel CRM Deployment, Server Infrastructure component)17.0 - 26.7
Estimated exposure
moderate≈ low thousands of internet-reachable Siebel deployments; total installed base likely in the tens of thousands of enterprise installations — Siebel CRM is legacy enterprise software typically deployed inside corporate networks, and public internet scans (Shodan/Censys) historically show only a few thousand exposed Siebel gateway/server endpoints at any time, so exposure is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.