CVE-2026-83193
nicheAuthenticated Takeover Flaw in Oracle Siebel Life Sciences (Siebel CRM 17.0-26.7)
CVE-2026-83193 is a flaw in the Life Sciences component of Oracle Siebel Apps (part of Oracle Siebel CRM), affecting supported versions 17.0 through 26.7. A low-privileged attacker who already has logon access to the infrastructure where the Siebel Life Sciences application executes can exploit this easily, but successful attacks require human interaction from a person other than the attacker (e.g., enticing a legitimate user to interact with attacker-controlled content). A successful attack results in complete takeover of the Siebel Life Sciences application, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.3). The attack vector is local, so the population at risk is limited to authenticated insiders or attackers who already have a foothold on Siebel infrastructure at organizations using the Life Sciences module. No public proof-of-concept exists, the flaw is not on the CISA Known Exploited Vulnerabilities list, and no in-the-wild exploitation is known.
What to do: Apply the Oracle Critical Patch Update addressing CVE-2026-83193 to all Siebel CRM Life Sciences deployments running versions 17.0-26.7. Because exploitation requires an authenticated local foothold plus user interaction, enforce least-privilege on operating-system and application accounts on Siebel servers, and coach users against interacting with unsolicited links or requests. Review Life Sciences accounts and configurations for unauthorized changes or anomalous privileged activity as a post-patch hygiene check.
| Oracle Siebel CRM - Siebel Apps Life Sciences (component: Life Sciences) | 17.0 - 26.7 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Siebel Apps - Life Sciences product of Oracle Siebel CRM (component: Life Sciences). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel Apps - Life Sciences executes to compromise Siebel Apps - Life Sciences. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Siebel Apps - Life Sciences. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.