ZeroHour

CVE-2026-83199

moderate

Privilege Escalation Leading to Full Takeover in Oracle Siebel CRM Deployment

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83199 is a high-severity (CVSS 8.8) vulnerability in the Server Infrastructure component of Oracle Siebel CRM's Deployment product, affecting supported versions 17.0 through 26.7. A low-privileged attacker with network access via HTTP can trigger the flaw, which Oracle rates as easily exploitable, and ultimately compromise the Siebel CRM Deployment, gaining full takeover with high impact on confidentiality, integrity, and availability. Any organization running an affected Siebel CRM version with the Deployment/Server Infrastructure component reachable over the network is exposed, particularly if low-privilege accounts (including self-registered or internal users) exist. Because the vulnerability requires only low privileges and no user interaction, compromised or insider low-tier accounts can be leveraged for full system compromise. No public proof of concept is known and the flaw is not on the CISA Known Exploited Vulnerabilities catalog, so exploitation in the wild is not currently indicated.

What to do: Apply the Oracle Critical Patch Update that remediates this flaw to all Siebel CRM installations running versions 17.0-26.7, prioritizing the Siebel CRM Deployment/Server Infrastructure component. Restrict HTTP/network access to Siebel servers to trusted VPN or internal networks, enforce least-privilege on Siebel user accounts, and review logs for suspicious activity by low-privilege accounts against deployment or server infrastructure endpoints.

Affected
Oracle Siebel CRM (Siebel CRM Deployment, component: Server Infrastructure)17.0-26.7
Estimated exposure
moderateestimated low thousands of enterprise deployments worldwide (each serving many internal users) — Siebel CRM is a large-enterprise, on-premises-heavy CRM with a customer base historically measured in the low thousands of organizations rather than millions of instances, so the count of affected installations is plausibly in the 1k-10k…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.