ZeroHour

CVE-2026-83201

moderate

Unauthenticated Critical Data Access and Modification in Oracle Siebel CRM Deployment (Server Infrastructure)

CVSS 3.1
9.1 critical
EPSS
Published
()
Modified
AI analysis

Oracle Siebel CRM's Deployment product (Server Infrastructure component) contains an easily exploitable flaw affecting versions 17.0 through 26.7 that allows an unauthenticated attacker with network access via HTTP to compromise the Siebel CRM Deployment component. Exploitation requires no privileges, no user interaction, and low attack complexity, letting a remote attacker create, delete, or modify critical data as well as read all data accessible to the component. The vulnerability carries a CVSS 3.1 base score of 9.1, with high confidentiality and integrity impacts and no availability impact, consistent with an authentication bypass or missing-authorization flaw rather than code execution. Any organization running a supported Siebel CRM release in the 17.0–26.7 range with HTTP-reachable Siebel server infrastructure is affected. The flaw is not in the CISA Known Exploited Vulnerabilities catalog and no public proof-of-concept is known, suggesting no observed in-the-wild exploitation to date.

What to do: Apply the relevant Oracle Critical Patch Update fix for your Siebel CRM release as soon as possible, since all supported versions from 17.0 through 26.7 are affected. Until patched, restrict network access to Siebel CRM Deployment/Server Infrastructure HTTP endpoints (e.g., via firewall rules, VPN, or reverse-proxy allowlisting) so they are not reachable by unauthenticated external users. Review audit logs and database change history for unexplained data creation, modification, or deletion, and rotate credentials associated with the Siebel Deployment component if anomalies are found.

Affected
Oracle Siebel CRM (Siebel CRM Deployment, Server Infrastructure component)17.0–26.7
Estimated exposure
moderateRoughly low thousands of internet-exposed Siebel server instances, with a larger population of tens of thousands of on-premises enterprise deployments… — Siebel CRM is an enterprise on-premises product deployed at large organizations worldwide, and public internet scan engines (e.g., Shodan/Censys) have historically shown only low thousands of internet-facing Siebel web/server endpoints, so…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Deployment accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.