ZeroHour

CVE-2026-83221

moderate

Authenticated SOAP Data-Access Flaw in Oracle Siebel CRM Integration (EAI)

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83221 is a high-severity vulnerability in the Siebel CRM Integration component (EAI - Enterprise Application Integration) of Oracle Siebel CRM, affecting versions 17.0 through 26.7. A low-privileged attacker with network access to the SOAP interface can exploit the flaw easily to gain unauthorized read access to all Siebel CRM Integration data, including critical data, as well as unauthorized update, insert, and delete access to some of that data (CVSS 3.1 base score 7.1; availability is not impacted). Any organization running a supported Siebel CRM deployment exposing the EAI/SOAP services to authenticated users is affected, though exploitation requires valid low-privilege credentials rather than anonymous access. There is no known public proof-of-concept and the CVE does not appear in CISA's Known Exploited Vulnerabilities catalog, so exploitation status is none known at this time.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83221 as soon as it is available for your Siebel version (17.0-26.7 are all affected). In the interim, restrict network access to Siebel EAI/SOAP endpoints (e.g., restrict to trusted networks or VPN, enforce authentication at a gateway) and apply least-privilege roles to accounts that can invoke EAI services. Review Siebel audit logs for unusual read, insert, update, or delete activity by low-privileged accounts against integration data.

Affected
Oracle Siebel CRM (Siebel CRM Integration, component: EAI)17.0-26.7
Estimated exposure
moderatelikely a few thousand enterprise Siebel deployments worldwide, potentially serving hundreds of thousands of end users (clearly an estimate) — Oracle Siebel CRM is legacy enterprise software concentrated in large organizations (financial services, telecom, government), with industry estimates typically placing active global deployments in the low thousands rather than tens of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: EAI). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Siebel CRM Integration. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data as well as unauthorized update, insert or delete access to some of Siebel CRM Integration accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.