Description
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.7. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Cloud Applications accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-09-15
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Manipulation and Access
Action: Immediate Patch
AI Analysis

Impact

A flaw in Siebel CRM Cloud Applications permits an unauthenticated attacker with physical network access to the hardware that hosts the application to create, modify, or delete data, as well as to read any data stored in the system violations without affecting availability.

Affected Systems

The issue affects Oracle Siebel CRM Cloud Applications versions 22.3 through 26.7. Users of these versions should check which release they are running and plan an upgrade or patch. No other products or versions are specifically noted in the report.

Risk and Exploitability

The base CVSS score of 8.1 highlights high impact, while the EPSS score of less than 1% indicates that the vulnerability is not widely exploited as of now and it is not listed in the CISA KEV catalog. The vulnerability is exploitable from the adjacent network, meaning that anyone with physical or local network connectivity to the machine can trigger the flaw without authentication. The risk is therefore significant for environments that do not isolate the Siebel environment from other local hosts.

Generated by OpenCVE AI on September 17, 2026 at 03:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch or upgrade to a version newer than 26.7 to fix the vulnerability.
  • If a patch is not immediately available, isolate the Siebel CRM hardware by blocking all non‑essential physical network ports and enforce strict network segmentation so that only authorized systems can reach the application host.
  • Deploy additional authentication mechanisms or access controls on the Siebel service to ensure that even local network users must authenticate before performing any data‑manipulation operations.

Generated by OpenCVE AI on September 17, 2026 at 03:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Physical Access Grants Unauthorized Data Manipulation in Siebel CRM Cloud Applications
Weaknesses CWE-284
CWE-306

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.7. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Cloud Applications accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle siebel Crm Cloud Applications
CPEs cpe:2.3:a:oracle:siebel_crm_cloud_applications:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Cloud Applications
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Siebel Crm Cloud Applications
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T20:03:13.604Z

Reserved: 2026-08-31T15:40:57.338Z

Link: CVE-2026-83073

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:16.247

Modified: 2026-09-16T19:36:43.087

Link: CVE-2026-83073

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T03:30:05Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-306

    Missing Authentication for Critical Function