ZeroHour

CVE-2026-83224

moderate

Low-Privilege Data Exposure and Partial DoS Flaw in Oracle Siebel CRM Server Infrastructure

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83224 is a high-severity (CVSS 7.1) vulnerability in the Server Infrastructure component of the Siebel CRM Deployment product, affecting an unusually broad range of supported versions from 17.0 through 26.7. It is easily exploitable by an authenticated, low-privileged attacker who has network access to the Siebel CRM Deployment over HTTP, requiring no user interaction. A successful attack lets the attacker read critical data or all Siebel CRM Deployment-accessible data, and to cause a partial denial of service; integrity is not impacted per the CVSS vector. The affected population is organizations running Oracle Siebel CRM on-premises or in private deployments, with any low-privilege account (e.g., a standard CRM user) being a viable starting point. There is no known public proof-of-concept, and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation status is none known.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83224 — because every supported version from 17.0 to 26.7 is affected, no current release is safe unpatched, so prioritize this CPU across all Siebel environments. In the interim, restrict HTTP access to Siebel application servers via IP allowlisting or VPN, audit and minimize low-privileged account grants, and review logs for anomalous authenticated data access or availability degradation. Verify that SWSE/Siebel server components are included in patching, not just the gateway.

Affected
Oracle Siebel CRM (Siebel CRM Deployment - Server Infrastructure component)17.0 - 26.7
Estimated exposure
moderatelikely low thousands of internet-reachable Siebel deployments (estimate); total downstream CRM users unknown — Siebel CRM is an on-premises enterprise CRM used mainly by large organizations and typically deployed behind firewalls or VPNs, with public internet scan services historically showing only a few thousand exposed instances, so the bulk of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM Deployment. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L

In the news

No ingested article mentions this CVE yet.