Description
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote takeover of Siebel CRM Cloud Applications
Action: Patch Immediately
AI Analysis

Impact

The vulnerability resides in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications. A low‑privileged attacker who can reach the application over HTTP can exploit the flaw to gain full control of the system. The flaw leads to confidentiality, integrity, and availability compromise, allowing an attacker to take over the application entirely.

Affected Systems

The affected systems are Oracle Siebel CRM Cloud Applications versions 22.3 to 26.7. The issue affects all deployments of the Siebel Cloud Manager component within those version ranges.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity with full confidentiality, integrity, and availability impacts. The EPSS score is below 1%, suggesting that widespread exploitation is currently unlikely, and it is not yet cataloged in CISA's KEV. Nevertheless, the low attack‑vector complexity and necessity only for low‑privileged access mean that an attacker with network visibility could potentially exploit the flaw. The vulnerability is easily exploitable, and if successful, results in a complete takeover of the application.

Generated by OpenCVE AI on September 17, 2026 at 02:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle's patch or upgrade to the fixed version referenced in Oracle's security alert.
  • If a patch is not yet available, block inbound HTTP traffic to the Siebel Cloud Manager component from untrusted networks and enforce strict firewall rules.
  • Verify that the application enforces strict access control and authentication checks on all exposed endpoints to prevent exploitation by low‑privileged users.

Generated by OpenCVE AI on September 17, 2026 at 02:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Attack Allows Takeover of Oracle Siebel CRM Cloud Applications
Weaknesses CWE-284
CWE-287

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle siebel Crm Cloud Applications
CPEs cpe:2.3:a:oracle:siebel_crm_cloud_applications:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Cloud Applications
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Siebel Crm Cloud Applications
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T20:03:17.776Z

Reserved: 2026-08-31T15:40:57.338Z

Link: CVE-2026-83086

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:18.393

Modified: 2026-09-16T19:36:43.087

Link: CVE-2026-83086

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T03:00:19Z

Weaknesses