ZeroHour

CVE-2026-83220

niche

Unauthenticated Adjacent-Network Data Access in Oracle Siebel CRM Integration (Event Pub/Sub)

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83220 is a high-severity (CVSS 8.1) vulnerability in the Event Publish and Subscribe component of Oracle Siebel CRM Integration, affecting Release Updates 23.6 through 26.7. It is easily exploitable by an unauthenticated attacker who has access to the physical communication segment (same network/adjacent network) attached to the hardware where Siebel CRM Integration executes — no privileges or user interaction are required. A successful attack compromises the integration component, giving the attacker unauthorized ability to create, delete, or modify critical data (or all Siebel CRM Integration accessible data) as well as unauthorized read access to critical or all accessible data; availability is not impacted. Organizations running on-premises Siebel CRM Integration deployments within the affected version range are exposed, primarily from attackers already present on internal or data-center network segments. No public proof-of-concept is known, the flaw is not on the CISA KEV list, and no in-the-wild exploitation has been reported.

What to do: Apply Oracle's Critical Patch Update and upgrade Siebel CRM Integration to a Release Update newer than 26.7 containing the fix for this CVE. In the meantime, restrict network access to the Siebel integration/Event Publish and Subscribe endpoints to trusted hosts only using firewall rules, VLAN segmentation, or ACLs, since exploitation requires adjacency on the communication segment. Review audit and integration logs for unexplained data creation, deletion, or modification activity originating from unrecognized sources.

Affected
Oracle Siebel CRM (Siebel CRM Integration, Event Publish and Subscribe component)23.6-26.7
Estimated exposure
niche≈ low thousands of enterprise Siebel deployments (internal systems, not typically internet-exposed) — Siebel CRM is legacy-heavy enterprise software deployed on-premises at large organizations; the total customer base is on the order of a few thousand companies, and the adjacent-network attack vector further limits exposure to hosts…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Event Publish and Subscribe). Supported versions that are affected are 23.6-26.7. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Siebel CRM Integration executes to compromise Siebel CRM Integration. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Integration accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.