ZeroHour

CVE-2026-83227

moderate

Difficult-to-Exploit Takeover Flaw in Oracle Siebel CRM Integration (EAI)

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83227 is a difficult-to-exploit vulnerability in the EAI (Enterprise Application Integration) component of Siebel CRM Integration within Oracle Siebel CRM, affecting versions 17.0 through 26.7. A low-privileged, authenticated attacker with network access via HTTP who successfully exploits the flaw can fully compromise the Siebel CRM Integration stack, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.5). The attack requires no user interaction, but the high attack complexity means an attacker typically needs repeated attempts or specific conditions to succeed. Organizations running any supported Siebel CRM release in the affected range without the current Oracle Critical Patch Update are exposed, especially where EAI/HTTP integration endpoints are reachable by a broad base of low-privilege users. No public proof of concept exists and the flaw is not on CISA's Known Exploited Vulnerabilities list, so exploitation in the wild is not known.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83227 to every Siebel CRM deployment in the 17.0-26.7 range, prioritizing environments where EAI/HTTP endpoints are broadly reachable. Until patched, restrict network access to EAI and HTTP integration endpoints to trusted sources, and audit low-privilege accounts for signs of abuse. Monitor Siebel integration logs for anomalous or repeated failed requests from low-privilege users, which could indicate exploitation attempts.

Affected
Oracle Siebel CRM (Siebel CRM Integration, EAI component)17.0-26.7
Estimated exposure
moderate≈ low thousands of internet-exposed Siebel endpoints, plus thousands more internal enterprise deployments (clearly an estimate) — Siebel CRM is an enterprise, largely on-premises product deployed by large organizations in government, telecom, and finance, and public internet-wide scans typically show only low-thousands of reachable Siebel web/EAI endpoints, so the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: EAI). Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Integration. Successful attacks of this vulnerability can result in takeover of Siebel CRM Integration. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.