ZeroHour

CVE-2026-83195

moderate

Privilege-Required Takeover Flaw in Oracle Siebel CRM Deployment (Server Infrastructure)

CVSS 3.1
7.2 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83195 is a vulnerability in the Server Infrastructure component of the Siebel CRM Deployment product of Oracle Siebel CRM, affecting supported versions 17.0 through 26.7. It is remotely exploitable over TCP and rated 'easily exploitable,' but it requires a high-privileged attacker (such as an administrator-level account) with network access to the Siebel server. A successful attack allows the attacker to fully compromise the Siebel CRM Deployment, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.2). Organizations running any supported Siebel CRM release in the affected range are exposed, though the high privilege requirement means the primary risk is from malicious insiders, compromised admin credentials, or lateral movement by attackers who already hold elevated access. No public proof-of-concept exists and the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog, so exploitation is not currently known to be occurring.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83195 to all Siebel CRM environments running versions 17.0 through 26.7. Restrict TCP network access to Siebel Server Infrastructure ports to trusted administrative networks or VPNs only, and audit high-privileged Siebel accounts for compromise or anomalous behavior, since exploitation requires existing elevated privileges. Verify that Development/Test environments running affected versions receive the same patching attention as production.

Affected
Oracle Siebel CRM (Siebel CRM Deployment, Server Infrastructure component)17.0 - 26.7 (supported versions)
Estimated exposure
moderate≈1,000-10,000 enterprise deployments, affecting potentially hundreds of thousands of end users (estimate) — Siebel CRM is a legacy on-premises enterprise CRM deployed mainly at large organizations; Oracle publishes no install counts, and public internet scan data suggests only a small fraction of server infrastructure is directly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows high privileged attacker with network access via TCP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.