CVE-2026-83208
moderateSQL-Triggered Takeover of Oracle Siebel CRM Deployment (Versions 17.0-26.7)
CVE-2026-83208 is a high-severity flaw (CVSS 8.8) in the Migration component of Oracle Siebel CRM Deployment, affecting supported versions 17.0 through 26.7. It is easily exploitable by a low-privileged attacker who has network access via SQL, allowing them to compromise the Siebel CRM Deployment entirely. A successful attack results in full takeover, with high impact on the confidentiality, integrity, and availability of the deployment. Any organization running an affected Siebel CRM version with reachable SQL/database interfaces and attacker-obtainable low-privileged credentials is exposed. No public proof-of-concept exists and the flaw is not on the CISA KEV list, so exploitation status is currently none known.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83208 to all Siebel CRM Deployment installations running versions 17.0-26.7, prioritizing environments where the Migration component is in use. Restrict network-level access to the Siebel database SQL listeners (e.g., via firewalls/IP allowlisting) so only trusted application and admin hosts can connect, and enforce least-privilege on database accounts used by Siebel. Review database audit logs for anomalous or unauthorized SQL activity originating from low-privileged accounts as an indicator of attempted exploitation.
| Oracle Siebel CRM (Siebel CRM Deployment, Migration component) | 17.0-26.7 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Migration). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.