ZeroHour

CVE-2026-83216

moderate

Local Privilege Escalation Enables Full Takeover of Oracle Siebel CRM Deployment

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

Oracle Siebel CRM Deployment contains an easily exploitable flaw in its Server Infrastructure component, affecting supported versions 17.0 through 26.7. A low-privileged attacker who already has a logon to the operating system or infrastructure where Siebel CRM Deployment executes can trigger the flaw without user interaction and take complete control of the Siebel CRM Deployment. Successful exploitation results in full compromise of confidentiality, integrity, and availability of the deployment (CVSS 3.1 base score 7.8, attack vector: local). The affected population is organizations running on-premises Siebel CRM installations within the listed version range, since the attack requires local access to the server host. No public proof-of-concept exists, the flaw is not on the CISA Known Exploited Vulnerabilities list, and no in-the-wild exploitation has been reported.

What to do: Apply the Oracle Critical Patch Update that remediates this issue, moving to a Siebel CRM version newer than the affected 17.0-26.7 range. Because exploitation requires only a low-privileged local account on the Siebel server host, restrict and audit OS-level logons to Siebel Deployment servers, enforce least privilege, and monitor for unexpected local session activity or privilege anomalies on those hosts.

Affected
Oracle Siebel CRM (Siebel CRM Deployment, Server Infrastructure component)17.0 - 26.7
Estimated exposure
moderatelow thousands of enterprise Siebel CRM deployments worldwide (each potentially serving many internal users); exact count not public — Siebel is an enterprise, predominantly on-premises CRM with no published install counts and few internet-exposed hosts in public scans, so I estimated low thousands of deployments based on typical enterprise deployment patterns for this…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Deployment executes to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.