ZeroHour

CVE-2026-83212

moderate

Low-Privilege Takeover Flaw in Oracle Siebel CRM Self Service (Helpdesk/Training)

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83212 is a high-severity (CVSS 8.8) vulnerability in the Helpdesk/Training component of Oracle Siebel Apps - Self Service, affecting supported versions 17.0 through 26.7. It is easily exploitable by an authenticated, low-privileged attacker with network access over HTTP, requiring no user interaction. A successful attack allows the attacker to fully compromise the Self Service application, with high impact on confidentiality, integrity, and availability — effectively a takeover of the affected deployment. Organizations running any supported Siebel CRM release in the affected range with the Self Service application exposed to users are at risk, particularly portals reachable from untrusted networks. No public proof-of-concept exists and the flaw is not on the CISA KEV list, so exploitation is not currently known to be occurring in the wild.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83212, upgrading affected Self Service deployments beyond the 26.7-or-earlier code line as directed by Oracle's advisory. Until patched, restrict HTTP access to the Self Service portal (VPN or IP allowlisting) and enforce least-privilege accounts for portal users. Review audit logs for anomalous activity by low-privileged accounts in the Helpdesk/Training component that could indicate exploitation attempts.

Affected
Oracle Siebel Apps - Self Service (Siebel CRM, component: Helpdesk/Training)17.0 - 26.7 (all supported versions in this range)
Estimated exposure
moderatelikely on the order of 1,000s of enterprise installations, with an unknown but larger end-user count — Siebel CRM is a legacy enterprise platform with a shrinking but still substantial installed base of large organizations, and Self Service portals are typically internet-facing by design; precise counts from public scan data are not…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel Apps - Self Service product of Oracle Siebel CRM (component: Helpdesk/Training). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps - Self Service. Successful attacks of this vulnerability can result in takeover of Siebel Apps - Self Service. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.