ZeroHour

CVE-2026-83326

moderate

Unauthenticated Data Exposure in Oracle Siebel CRM Integration (Open Integration)

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83326 is a high-severity (CVSS 7.5) information disclosure flaw in the Open Integration component of Oracle Siebel CRM Integration, affecting releases 25.12 through 26.7. An unauthenticated remote attacker can trigger the flaw by sending crafted HTTP requests to a network-reachable Siebel CRM Integration endpoint, with no user interaction or privileges required. A successful attack yields unauthorized access to critical data, up to complete access to all data reachable through Siebel CRM Integration, though integrity and availability are not impacted. Organizations running Siebel CRM versions 25.12–26.7 with integration endpoints exposed to untrusted networks are the primary concern. No public proof-of-concept exists and the vulnerability is not on CISA's KEV list, so exploitation is not currently known.

What to do: Apply Oracle's Critical Patch Update that addresses CVE-2026-83326 to all Siebel CRM Integration instances running versions 25.12–26.7. Until patched, restrict network access to Open Integration endpoints (firewall rules, reverse proxy allow-lists, VPN) and enable logging/alerting on unauthenticated requests to those endpoints. Review access logs for anomalous data retrieval from integration services to rule out prior exploitation.

Affected
Oracle Siebel CRM (Siebel CRM Integration, Open Integration component)25.12–26.7
Estimated exposure
moderatelow thousands of enterprise Siebel CRM deployments; unknown number with internet-exposed Open Integration endpoints — Siebel CRM is deployed by a few thousand large enterprises (typically on-premise or private cloud), and no public scan or install-count data was available to firm up the exposed-endpoint figure.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions that are affected are 25.12-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.