Description
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via SSH to compromise Siebel CRM Cloud Applications. While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-09-15
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized remote access to sensitive data
Action: Apply patch
AI Analysis

Impact

A flaw in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications allows an attacker who can reach the system over SSH to gain unauthenticated access to all customer data. The vulnerability is an access‑control weakness (CWE‑284) that bypass to read or modify any information stored in the application. The impact is a severe compromise of confidentiality with no direct effect on integrity or availability, as reflected by the CVSS 3.1 score of 8.6.

Affected Systems

Oracle Corporation: Siebel CRM Cloud Applications, specifically the Siebel Cloud Manager component. Versions ranging from 22.3 through 26.7 are affected.|

Risk and Exploitability

The flaw can be exploited by any actor with network reach to the SSH service—no credentials required. The EPSS score of <1% suggests that real‑world exploitation is currently rare, but the high CVSS score and absence from the CISA KEV list indicate that the vulnerability remains a significant threat. Because the scope change is noted, compromise can potentially spread to other foothold is established. An attacker could read, copy, or delete business‑critical data, exposing the organization to financial loss, regulatory penalties, or reputational damage.

Generated by OpenCVE AI on September 17, 2026 at 03:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle Siebel CRM Cloud Applications to a version beyond 26.7 that patches CVE-2026-83074
  • Restrict SSH access to the application host to trusted networks or IP ranges using firewall or IAM controls
  • Enforce SSH key‑based to reduce the attack surface
  • Apply strict role‑based access control to limit who can create or modify SSH sessions

Generated by OpenCVE AI on September 17, 2026 at 03:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via SSH to compromise Siebel CRM Cloud Applications. While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle siebel Crm Cloud Applications
CPEs cpe:2.3:a:oracle:siebel_crm_cloud_applications:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Cloud Applications
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Siebel Crm Cloud Applications
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T17:59:13.309Z

Reserved: 2026-08-31T15:40:57.338Z

Link: CVE-2026-83074

cve-icon Vulnrichment

Updated: 2026-09-16T17:52:05.664Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:17.027

Modified: 2026-09-16T19:40:00.317

Link: CVE-2026-83074

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T04:00:20Z

Weaknesses