ZeroHour

CVE-2026-83210

moderate

SQL-Accessible Takeover Flaw in Oracle Siebel CRM Deployment (Server Infrastructure)

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83210 is a high-severity (CVSS 3.1: 8.8) vulnerability in the Siebel CRM Deployment component of Oracle Siebel CRM, specifically in the Server Infrastructure layer, affecting supported versions 17.0 through 26.7. A low-privileged attacker with network access who can reach the product via SQL can exploit this flaw easily, without user interaction, to fully compromise the Siebel CRM Deployment. Successful attacks result in a complete takeover, with high impact on the confidentiality, integrity, and availability of the affected deployment. Any organization running a supported Siebel CRM version in the 17.0-26.7 range is affected, though exploitation requires an attacker to already hold low-privileged credentials and network reach to the database-facing interface. No public proof-of-concept exists, the issue is not on the CISA KEV list, and no exploitation in the wild has been reported.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83210 to all Siebel CRM Deployment instances running versions 17.0-26.7, prioritizing deployments where end users or integrations hold low-privileged database accounts. Restrict network access to the SQL-facing interface so only trusted application and administration hosts can reach it, and enforce least-privilege on Siebel database accounts. Review database audit logs for anomalous SQL activity from low-privileged accounts as an indicator of attempted exploitation.

Affected
Oracle Siebel CRM (Siebel CRM Deployment, component: Server Infrastructure)17.0-26.7
Estimated exposure
moderate≈ low thousands of enterprise deployments (order of magnitude 1k-10k installations) — Siebel CRM is an enterprise on-premises customer-engagement suite deployed at thousands of large organizations worldwide, typically on internal networks rather than internet-exposed endpoints, so no public scan or install-count data exists…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.