ZeroHour

CVE-2026-83202

moderate

Unauthenticated Critical Data Access and Modification in Oracle Siebel CRM (17.0-26.7)

CVSS 3.1
9.1 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-83202 is a critical (CVSS 9.1) flaw in the Server Infrastructure component of Oracle Siebel CRM Deployment, affecting supported versions 17.0 through 26.7. It is easily exploitable by an unauthenticated attacker with network access via HTTP, meaning no valid credentials or user interaction are required. A successful attack allows the attacker to create, delete, or modify critical data (or all data accessible to the Siebel CRM Deployment component), as well as read critical or all accessible data; availability is not impacted. Organizations running affected Siebel CRM versions with the deployment/server infrastructure reachable over a network — especially internet-exposed Siebel web endpoints — are at risk of silent data theft and tampering. The flaw is not in the CISA KEV catalog and no public proof-of-concept is known, so exploitation status is currently none known.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83202 and move to a Siebel CRM release beyond the affected 17.0-26.7 range. Until patched, restrict HTTP access to Siebel Deployment/Server Infrastructure endpoints using firewalls, reverse proxies, or VPN-only access, and disable any unnecessary internet exposure. Review application and database audit logs for unauthenticated access patterns and unexplained creation, modification, or deletion of Siebel data.

Affected
Oracle Siebel CRM (Siebel CRM Deployment, component: Server Infrastructure)17.0 - 26.7
Estimated exposure
moderate≈1,000-10,000 internet-exposed Siebel deployments, plus a larger but unknown number of internal-only enterprise instances — Siebel is on-premises enterprise software with an installed base of thousands of organizations, and public internet scans (Shodan/Censys-type) typically show low thousands of reachable Siebel web server endpoints; most deployments sit on…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Deployment accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.