ZeroHour

CVE-2026-83230

moderate

Authenticated Data Exposure in Oracle Siebel CRM Management Console (17.0-26.7)

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83230 is an improper-authorization vulnerability in the Siebel Management Console component of Oracle Siebel CRM Deployment, affecting all supported releases from 17.0 through 26.7. A low-privileged attacker with valid credentials and network access via HTTP can send crafted requests to the management console to gain unauthorized read access to critical data — or complete access to all Siebel CRM Deployment accessible data — as well as unauthorized update, insert, or delete access to some of that data. The flaw is rated High severity with a CVSS 3.1 base score of 7.1 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N), meaning it is easily exploitable once any low-privilege account is obtained, with no user interaction required. In practice, any organization running a supported Siebel CRM deployment with the management console reachable over the network is affected. There is no known public proof-of-concept, the CVE is not on the CISA Known Exploited Vulnerabilities list, and no in-the-wild exploitation has been reported, though a fix should arrive through Oracle's Critical Patch Update cycle.

What to do: Apply the Oracle Critical Patch Update that addresses this CVE as soon as it is released, since every supported release from 17.0 to 26.7 is affected. In the meantime, restrict network access to the Siebel Management Console (VPN, IP allowlisting, internal-only routing), audit low-privileged accounts for abuse, and review console logs for unexpected read or write activity. Also verify that least-privilege role assignments are enforced for all accounts with HTTP access to the deployment environment.

Affected
Oracle Siebel CRM (Siebel CRM Deployment — Siebel Management Console component)17.0-26.7 (all supported releases in this range)
Estimated exposure
moderate≈1,000–10,000 enterprise deployments globally, with likely only hundreds of internet-exposed management consoles — Siebel CRM is on-premises enterprise software concentrated among large organizations, and public internet scans typically show only a few hundred directly exposed Siebel management endpoints since the console is usually deployed on…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Siebel Management Console). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data as well as unauthorized update, insert or delete access to some of Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.