CVE-2026-83196
moderatePrivileged HTTP Takeover Flaw in Oracle Siebel CRM Deployment (Server Infrastructure)
CVE-2026-83196 is a critical (CVSS 9.1) vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM, specifically in the Server Infrastructure component, affecting supported versions 17.0 through 26.7. It is remotely exploitable over HTTP but requires a high-privileged attacker (such as an administrator with valid credentials), which lowers the realistic attack surface to insider threats, compromised admin accounts, or credential-theft-driven attacks. Because the vulnerability has a scope change (S:C), successful exploitation can significantly impact products beyond Siebel CRM Deployment, and a successful attack results in complete takeover of the Siebel CRM Deployment component with high impact to confidentiality, integrity, and availability. Organizations running affected Siebel CRM versions are exposed, particularly if the deployment/management interfaces are reachable over the network. No public proof-of-concept exists and the flaw is not on the CISA KEV list, so no active exploitation is known.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83196 to all Siebel CRM deployments in the 17.0–26.7 range. Restrict network/HTTP access to the Siebel Deployment and Server Infrastructure management interfaces to trusted admin networks only, and enforce MFA on high-privileged Siebel accounts since exploitation requires elevated privileges. Review audit logs for anomalous activity by privileged accounts against deployment endpoints and verify that scope-change impacts on adjacent integrated systems have been assessed.
| Oracle Siebel CRM (Siebel CRM Deployment, Server Infrastructure component) | 17.0 - 26.7 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. While the vulnerability is in Siebel CRM Deployment, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.