ZeroHour

CVE-2026-83211

niche

Local Privilege Escalation to Full Takeover in Oracle Siebel CRM Deployment (17.0-26.7)

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

A high-severity (CVSS 7.8) vulnerability in the Server Infrastructure component of Oracle Siebel CRM Deployment allows a low-privileged attacker who already has logon access to the host where Siebel CRM Deployment executes to compromise the entire deployment. The flaw is local (AV:L), requires only low privileges and no user interaction, and is described by Oracle as easily exploitable. Successful exploitation results in complete takeover of Siebel CRM Deployment with high impact to confidentiality, integrity, and availability — effectively full control of the CRM system and its business data. Affected organizations are those running supported Siebel CRM versions 17.0 through 26.7 on servers accessible to low-privileged local or OS-level accounts. No public proof-of-concept exists and the vulnerability is not in CISA's Known Exploited Vulnerabilities catalog, so exploitation is presumed to be theoretical at this time.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83211 to all Siebel CRM Deployment installations running versions 17.0-26.7. Restrict OS-level logon access to Siebel servers to only necessary administrative accounts, run Siebel services under least-privileged accounts, and audit local account activity on those hosts for signs of privilege escalation. Verify that the patched version exceeds the affected 17.0-26.7 range after remediation.

Affected
Oracle Siebel CRM (Siebel CRM Deployment, Server Infrastructure component)17.0-26.7
Estimated exposure
nichelikely low thousands of enterprise deployments worldwide — Siebel CRM is legacy on-premises enterprise software deployed primarily at large organizations, and there is no public scan or install-count telemetry to give a firmer number, so this is a rough order-of-magnitude guess.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Deployment executes to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.