ZeroHour

CVE-2026-83207

moderate

Low-Privilege DoS and Data Tampering in Oracle Siebel CRM Development Scripting

CVSS 3.1
7.6 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83207 is a vulnerability in the Integration - Scripting component of the Siebel CRM Development product of Oracle Siebel CRM, affecting supported versions 17.0 through 26.7. It is easily exploitable by a low-privileged (authenticated) attacker with network access via HTTP, requiring no user interaction. A successful attack can cause a complete denial of service (hang or frequently repeatable crash) of the Siebel CRM Development environment, and can also give the attacker unauthorized update, insert, and delete access to some accessible data plus unauthorized read access to a subset of that data. The flaw is scored CVSS 3.1 7.6 (high) with availability impact being the most severe consequence. It is not listed in the CISA KEV catalog, no public proof-of-concept is known, and no in-the-wild exploitation has been reported.

What to do: Apply Oracle's Critical Patch Update that remediates this CVE; all supported versions 17.0 through 26.7 are affected, so installations must move to a patched release. Restrict network/HTTP access to Siebel CRM Development environments to trusted users and segments, enforce least-privilege roles for low-privileged accounts, and review logs for anomalous scripting/integration activity or repeated crashes indicating exploitation attempts.

Affected
Oracle Siebel CRM (Development product, component: Integration - Scripting)17.0 - 26.7
Estimated exposure
moderatelikely on the order of thousands of enterprise deployments worldwide (clearly an estimate) — Siebel CRM is an on-premises enterprise CRM deployed mainly at large organizations (banks, telcos, government) with no public active-install telemetry, so exposure is estimated from its enterprise-only deployment pattern rather than plugin…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Integration - Scripting). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Development. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Development as well as unauthorized update, insert or delete access to some of Siebel CRM Development accessible data and unauthorized read access to a subset of Siebel CRM Development accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H

In the news

No ingested article mentions this CVE yet.