ZeroHour

CVE-2026-83229

moderate

Privileged Takeover Flaw in Oracle Siebel CRM Management Console (v17.0-26.7)

CVSS 3.1
9.1 critical
EPSS
Published
()
Modified
AI analysis

A critical vulnerability (CVSS 9.1) exists in the Siebel Management Console component of Oracle Siebel CRM Deployment, affecting supported versions 17.0 through 26.7. It is easily exploitable by a high-privileged attacker with network access via HTTP, allowing them to fully compromise the Siebel CRM Deployment. The vulnerability has a scope change (S:C), meaning successful attacks can significantly impact additional products beyond the Siebel CRM Deployment component itself. Successful exploitation results in a complete takeover of the deployment with high impacts to confidentiality, integrity, and availability. There is no evidence of in-the-wild exploitation, and no public proof-of-concept is known.

What to do: Apply the Oracle Critical Patch Update that remediates this flaw to all Siebel CRM deployments running versions 17.0-26.7. Restrict network access to the Siebel Management Console so it is reachable only from trusted administrative networks, and enforce least-privilege on the high-privileged accounts that could be leveraged in an attack. Audit Management Console logs for anomalous activity by high-privilege accounts and monitor for unexpected configuration or deployment changes.

Affected
Oracle Siebel CRM (Siebel CRM Deployment - Siebel Management Console component)17.0 - 26.7
Estimated exposure
moderate≈1,000-10,000 enterprise deployments globally (likely only a subset with internet-exposed Management Consoles) — Siebel CRM is a legacy on-premises enterprise suite deployed primarily by large organizations, and the vulnerable Management Console is typically internal-facing, so the number of affected systems is estimated in the low thousands with an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Siebel Management Console). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. While the vulnerability is in Siebel CRM Deployment, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.