CVE-2026-83223
moderateDifficult-to-Exploit Authenticated Takeover Flaw in Oracle Siebel CRM (Siebel Remote)
CVE-2026-83223 is a difficult-to-exploit vulnerability in the Siebel Remote component of Oracle Siebel CRM Deployment, affecting all supported releases from 17.0 through 26.7. A remote attacker who already holds a low-privileged account and has network access via HTTP can exploit the flaw to fully compromise the Siebel CRM Deployment, with high impacts on confidentiality, integrity, and availability (CVSS 3.1 base score 7.5). The high attack complexity means exploitation is not trivial and likely requires specific conditions or race-type behavior, but successful attacks result in complete takeover of the deployment. Organizations running on-premises Siebel CRM with Siebel Remote exposed to broader networks (including employee-facing or internet-reachable HTTP endpoints) are the primary concern. The flaw is not on the CISA KEV list, no public proof of concept is known, and there is no indication of in-the-wild exploitation at this time.
What to do: Apply the Oracle Critical Patch Update that addresses this issue and move to a Siebel CRM release patched for CVE-2026-83223 (the fixed code ships in releases after 26.7 or via the corresponding CPU patch). Restrict network access to Siebel Remote and related HTTP endpoints to trusted internal networks or VPN, and audit low-privileged accounts for suspicious activity. Verify that Siebel deployments on versions 17.0 through 26.7 are inventoried and prioritized for patching.
| Oracle Siebel CRM (Siebel CRM Deployment, component: Siebel Remote) | 17.0 - 26.7 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Siebel Remote). Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.