ZeroHour

CVE-2026-83222

moderate

Unauthenticated Denial-of-Service in Oracle Siebel CRM Server Infrastructure (17.0-26.7)

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83222 is an easily exploitable vulnerability in the Server Infrastructure component of Oracle Siebel CRM's Deployment product, affecting all supported versions from 17.0 through 26.7. An unauthenticated remote attacker with network access via multiple protocols can trigger the flaw, causing the Siebel CRM Deployment to hang or crash repeatedly — a complete denial of service. The vulnerability has no impact on confidentiality or integrity, but availability impact is high, earning a CVSS 3.1 base score of 7.5. Organizations running on-premises Siebel CRM deployments with network-reachable server infrastructure are the primary affected population. As of now, the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog and no public proof-of-concept is known.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83222 to all Siebel CRM Server Infrastructure installations running versions 17.0-26.7. Until patched, restrict network access to Siebel server ports (management, gateway, and application protocols) to trusted sources via firewall rules or VPN, since the flaw requires no authentication. Monitor Siebel Server logs for unexplained hangs or repeated crashes, which are the observable symptoms of attacks against this vulnerability.

Affected
Oracle Siebel CRM (Deployment / Server Infrastructure component)17.0 - 26.7
Estimated exposure
moderatelow thousands of organizations / server deployments globally (clearly an estimate) — Siebel CRM is heavyweight enterprise software deployed on-premises at large financial, telecom, pharmaceutical, and government organizations; no public internet-scan counts or active-install figures exist for it, so the estimate is based…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Deployment. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

Weakness
CWE-400
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.