CVE-2026-83207
moderateLow-Privilege DoS and Data Tampering in Oracle Siebel CRM Development Scripting
CVE-2026-83207 is a vulnerability in the Integration - Scripting component of the Siebel CRM Development product of Oracle Siebel CRM, affecting supported versions 17.0 through 26.7. It is easily exploitable by a low-privileged (authenticated) attacker with network access via HTTP, requiring no user interaction. A successful attack can cause a complete denial of service (hang or frequently repeatable crash) of the Siebel CRM Development environment, and can also give the attacker unauthorized update, insert, and delete access to some accessible data plus unauthorized read access to a subset of that data. The flaw is scored CVSS 3.1 7.6 (high) with availability impact being the most severe consequence. It is not listed in the CISA KEV catalog, no public proof-of-concept is known, and no in-the-wild exploitation has been reported.
What to do: Apply Oracle's Critical Patch Update that remediates this CVE; all supported versions 17.0 through 26.7 are affected, so installations must move to a patched release. Restrict network/HTTP access to Siebel CRM Development environments to trusted users and segments, enforce least-privilege roles for low-privileged accounts, and review logs for anomalous scripting/integration activity or repeated crashes indicating exploitation attempts.
| Oracle Siebel CRM (Development product, component: Integration - Scripting) | 17.0 - 26.7 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Integration - Scripting). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Development. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Development as well as unauthorized update, insert or delete access to some of Siebel CRM Development accessible data and unauthorized read access to a subset of Siebel CRM Development accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
In the news0 stories
No ingested article mentions this CVE yet.