ZeroHour

CVE-2026-83226

moderate

Difficult-to-Exploit Takeover Flaw in Oracle Siebel CRM Deployment 17.0-26.7

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83226 is a high-severity (CVSS 7.5) vulnerability in the Server Infrastructure component of Oracle Siebel CRM Deployment, affecting all supported versions from 17.0 through 26.7. A low-privileged, authenticated attacker with network access via HTTP can exploit the flaw — though exploitation is rated as difficult (AC:H) — and, if successful, take complete control of the Siebel CRM Deployment, with high impact on confidentiality, integrity, and availability. Any organization running an on-premises or internet-reachable Siebel CRM Deployment in the affected version range is at risk, particularly where low-privilege user accounts exist. There is no known public proof of concept and the flaw is not on the CISA Known Exploited Vulnerabilities list, indicating no observed in-the-wild exploitation to date. This appears to be addressed through Oracle's routine Critical Patch Update cycle, so timely patching closes the window.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83226 to every Siebel CRM Deployment running versions 17.0 through 26.7. Restrict HTTP access to Siebel Server Infrastructure and Deployment endpoints using IP allowlisting or VPN so only authenticated, low-privilege users you trust can reach them, and audit those accounts for abuse. Monitor Siebel and reverse-proxy logs for anomalous authenticated requests targeting deployment infrastructure.

Affected
Oracle Siebel CRM (Siebel CRM Deployment, Server Infrastructure component)17.0 - 26.7
Estimated exposure
moderate≈2,000-5,000 internet-exposed Siebel servers, out of an enterprise install base likely in the low tens of thousands of deployments — Internet-wide scans (Shodan/Censys-type sources) typically show a few thousand Siebel web endpoints exposed over HTTP, and Siebel is an on-premises enterprise CRM concentrated in large organizations, most of which sit behind corporate…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.