CVE-2026-83228
nicheUnauthenticated Denial-of-Service in Oracle Siebel CRM Server Infrastructure (17.0-26.7)
CVE-2026-83228 is an easily exploitable denial-of-service vulnerability in the Server Infrastructure component of Oracle Siebel CRM Deployment. An unauthenticated attacker with network access via TCP can send crafted requests that cause the Siebel CRM Deployment to hang or repeatedly crash, resulting in a complete denial of service. The flaw affects only availability — confidentiality and integrity are not impacted — and carries a CVSS 3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Any organization running Oracle Siebel CRM versions 17.0 through 26.7 with the affected server infrastructure reachable over the network is exposed. There is no known public proof of concept and no evidence of in-the-wild exploitation, and the issue is not on the CISA KEV list.
What to do: Apply the Oracle Critical Patch Update that remediates this vulnerability and move to a fixed Siebel CRM release above 26.7 as specified in the advisory. Restrict TCP access to Siebel server infrastructure ports (Gateway and application server services) to trusted internal networks and VPNs only, and never expose them directly to the internet. Monitor Siebel server logs for unexplained hangs or frequent restarts/crashes, which would be the primary indicator of an attempted attack.
| Oracle Siebel CRM (Siebel CRM Deployment - Server Infrastructure) | 17.0 - 26.7 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Deployment. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
- Weakness
- CWE-400
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.