Description
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.7. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Cloud Applications accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-09-15
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Manipulation and Access
Action: Immediate Patch
AI Analysis

Impact

A flaw in Siebel CRM Cloud Applications permits an unauthenticated attacker with physical network access to the hardware that hosts the application to create, modify, or delete data, as well as to read any data stored in the system. The vulnerability is a combination of improper authorization (CWE-284), allowing users without credentials to perform these actions without affecting availability.

Affected Systems

The issue affects Oracle Siebel CRM Cloud Applications versions 22.3 through 26.7. Users of these versions should check which release they are running and plan an upgrade or patch. No other products or versions are specifically noted in the report.

Risk and Exploitability

The base CVSS score of 8.1 highlights high impact, while the EPSS score of less than 1% indicates that the vulnerability is not widely exploited as of now and it is not listed in the CISA KEV catalog. The vulnerability is exploitable from the adjacent network, meaning that anyone with physical or local network connectivity to the machine can trigger the flaw without authentication. The risk is therefore significant for environments that do not isolate the Siebel environment from other local hosts.

Generated by OpenCVE AI on September 20, 2026 at 12:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Oracle patch or upgrade to a version newer than 26.7 to fix the vulnerability.
  • If a patch is not immediately available, isolate the Siebel CRM hardware by blocking all non‑essential physical network ports and enforce strict network segmentation so that only authorized systems can reach the application host.
  • Deploy additional authentication mechanisms or access controls on the Siebel service to ensure that even local network users must authenticate before performing any data‑manipulation operations.

Generated by OpenCVE AI on September 20, 2026 at 12:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Physical Network Access Allows Data Manipulation in Oracle Siebel CRM Cloud

Sun, 20 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Physical Access Grants Unauthorized Data Manipulation in Siebel CRM Cloud Applications
Weaknesses CWE-306

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Physical Access Grants Unauthorized Data Manipulation in Siebel CRM Cloud Applications
Weaknesses CWE-284
CWE-306

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.7. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Cloud Applications accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle siebel Crm Cloud Applications
CPEs cpe:2.3:a:oracle:siebel_crm_cloud_applications:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Cloud Applications
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Siebel Crm Cloud Applications
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:21:13.161Z

Reserved: 2026-08-31T15:40:57.338Z

Link: CVE-2026-83073

cve-icon Vulnrichment

Updated: 2026-09-17T14:59:12.547Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:16.247

Modified: 2026-09-17T16:17:55.913

Link: CVE-2026-83073

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T12:30:17Z

Weaknesses