ZeroHour

CVE-2026-83218

moderate

Unauthenticated Data Manipulation Flaw in Oracle Siebel CRM Deployment

CVSS 3.1
7.4 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83218 is a difficult-to-exploit vulnerability in the Server Infrastructure component of Oracle Siebel CRM Deployment, affecting supported versions 17.0 through 26.7. An unauthenticated attacker with network access via HTTP could trigger the flaw to compromise the Siebel CRM Deployment component, though the high attack complexity means successful exploitation requires favorable conditions and likely reconnaissance of the target. A successful attack results in unauthorized creation, deletion, or modification of critical data, or unauthorized read access to all data accessible through Siebel CRM Deployment (CVSS 3.1: 7.4, high; confidentiality and integrity impacted, availability not affected). Organizations running on-premises Siebel CRM deployments within the affected version range are exposed, particularly if Siebel HTTP endpoints are reachable by untrusted networks. No public proof-of-concept exists and the vulnerability is not in CISA's Known Exploited Vulnerabilities catalog, so no active exploitation is currently known.

What to do: Apply the Oracle Critical Patch Update that fixes CVE-2026-83218 to every Siebel CRM Deployment instance running versions 17.0 through 26.7, prioritizing any systems with HTTP endpoints reachable from untrusted networks. As an interim mitigation, restrict network access to Siebel Server Infrastructure HTTP services via firewall rules or VPN allow-listing. Review audit logs for unauthenticated data creation, deletion, or modification activity on Siebel Deployment-accessible data.

Affected
Oracle Siebel CRM (Siebel CRM Deployment, component: Server Infrastructure)17.0-26.7
Estimated exposure
moderatelow thousands of enterprise deployments (roughly 3,000-5,000 customer organizations worldwide) — Siebel CRM is a legacy enterprise on-premise CRM concentrated at large organizations in finance, telecom, pharma, and the public sector, with Siebel server HTTP endpoints typically internal- or VPN-facing rather than broadly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Deployment accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.