CVE-2026-83219
moderateLocal privilege escalation in Oracle Siebel CRM Server Infrastructure (17.0-26.7)
CVE-2026-83219 is an easily exploitable vulnerability in the Server Infrastructure component of Oracle Siebel CRM Deployment, affecting supported versions 17.0 through 26.7. It is triggered by a low-privileged attacker who has logon access to the machine or infrastructure where Siebel CRM Deployment executes (CVSS 3.1 vector AV:L/AC:L/PR:L/UI:N), meaning it requires a valid local or host-level account rather than network access. Successful exploitation lets the attacker compromise Siebel CRM Deployment entirely, gaining unauthorized creation, deletion, or modification of critical data as well as unauthorized read access to critical or all Siebel-accessible data. The impact is high for confidentiality and integrity, with no availability impact (base score 7.1). There is no known public proof of concept, no indication of in-the-wild exploitation, and the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog.
What to do: Apply the Oracle Critical Patch Update that addresses this flaw to all supported Siebel CRM Deployment installations running versions 17.0 through 26.7. Restrict and audit local OS accounts and interactive logon rights on Siebel application and server infrastructure hosts, since exploitation requires local logon with low privileges. Review Siebel data for unauthorized creation, deletion, or modification of critical records, and monitor host logs for unexpected access by low-privileged accounts.
| Oracle Siebel CRM (Siebel CRM Deployment, Server Infrastructure component) | 17.0 - 26.7 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Deployment executes to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Deployment accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.