CVE-2026-83213
moderateUnauthenticated Data Exposure in Oracle Siebel CRM Reports Component
CVE-2026-83213 is a high-severity (CVSS 7.5) information disclosure vulnerability in the Reports component of Oracle Siebel CRM's End User application, affecting versions 17.0 through 26.7. The flaw is easily exploitable: an unauthenticated attacker with network access to the Siebel server over HTTP can trigger it without any user interaction, requiring only low-complexity attack conditions. A successful attack allows the attacker to read critical data or gain complete access to all data reachable through the Siebel CRM End User application, with no impact on integrity or availability. Organizations running the affected Siebel CRM versions, particularly those with internet-facing Siebel endpoints, are at risk of exposure of customer and business data. No public proof-of-concept exists, the issue is not on the CISA KEV list, and no exploitation in the wild has been reported to date.
What to do: Apply the Oracle Critical Patch Update (CPU) that remediates CVE-2026-83213 to all Siebel CRM installations running versions 17.0-26.7. Restrict network access to Siebel End User and Reports endpoints so they are not directly reachable from the internet (VPN/reverse proxy with enforced authentication), and review HTTP access logs for unauthenticated requests targeting Reports URLs to rule out prior data access.
| Oracle Siebel CRM (End User, component: Reports) | 17.0-26.7 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Reports). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM End User. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM End User accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.