ZeroHour

CVE-2026-83215

moderate

Unauthenticated HTTP Data Access Flaw in Oracle Siebel CRM Server Infrastructure

CVSS 3.1
8.2 high
EPSS
Published
()
Modified
AI analysis

Oracle Siebel CRM's Deployment product contains a high-severity (CVSS 8.2) flaw in the Server Infrastructure component affecting all supported versions from 17.0 through 26.7. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges or user interaction. A successful attack can result in unauthorized read access to critical data — or complete access to all Siebel CRM Deployment-accessible data — as well as unauthorized update, insert, and delete access to some of that data; availability is not impacted. Any organization running a supported on-premises Siebel CRM Deployment in the affected range with HTTP-reachable server infrastructure is exposed. The flaw is not in the CISA Known Exploited Vulnerabilities catalog, no public proof of concept is known, and there are no reports of in-the-wild exploitation to date.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83215 to any Siebel CRM Deployment running versions 17.0-26.7. Until patched, restrict HTTP/network access to Siebel Server Infrastructure endpoints via VPN, IP allowlisting, or a reverse proxy/WAF so they are not reachable unauthenticated from the internet. Review server logs for unauthenticated HTTP requests and anomalous read, update, insert, or delete activity against Siebel-accessible data.

Affected
Oracle Siebel CRM (Siebel CRM Deployment, component: Server Infrastructure)17.0-26.7 (all supported versions in this range)
Estimated exposure
moderateOn the order of a few thousand internet-exposed Siebel deployments, with plausibly tens of thousands of enterprise installations overall — Siebel CRM is an on-premises enterprise CRM deployed mostly at large organizations, and public internet scan data for Siebel server endpoints typically shows low thousands of reachable instances, with the majority of deployments hosted…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data as well as unauthorized update, insert or delete access to some of Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.