Description
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Siebel CRM Deployment executes to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Deployment. CVSS 3.1 Base Score 7.3 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H).
Published: 2026-09-15
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Confidentiality breach and Availability disruption
Action: Assess Impact
AI Analysis

Impact

This vulnerability exists in the Server Infrastructure component of Oracle Siebel CRM Deployment, allowing a low‑privileged attacker who can reach the physical communication segment attached to the hardware to compromise the deployment. An attacker can obtain unauthorized access to critical data or all data available through the deployment, and can also force the system to hang or repeatedly crash, resulting in a complete denial‑of‑service.

Affected Systems

Affected are Oracle Siebel CRM Deployment versions 17.0 through 26.7, as identified by the vendor’s CNA.

Risk and Exploitability

The CVSS score of 7.3 indicates significant risk, while the EPSS score of less than 1% suggests current exploitation likelihood is low but not negligible, particularly for systems exposed to the adjacent network. The vulnerability is not listed in CISA’s KEV catalog, yet the local nature of the attack and low privilege requirement mean that exploitation remains feasible within an organization’s internal or physically adjacent network.

Generated by OpenCVE AI on September 20, 2026 at 09:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Restrict network traffic to the Siebel CRM Deployment servers using firewall or VLAN rules to limit adjacent‑network access
  • Monitor system logs and performance metrics for signs of unauthorized data access attempts or abnormal crashes, and investigate immediately
  • Check Oracle’s security advisories and official documentation for any future patch or remediation updates related to this vulnerability

Generated by OpenCVE AI on September 20, 2026 at 09:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Title Local Network Privilege Escalation and Denial of Service in Oracle Siebel CRM Deployment

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unrestricted Data Access and DoS via Physical Network Segment in Oracle Siebel CRM Deployment
Weaknesses CWE-400

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Title Unrestricted Data Access and DoS via Physical Network Segment in Oracle Siebel CRM Deployment
Weaknesses CWE-284
CWE-400

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Siebel CRM Deployment executes to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Deployment. CVSS 3.1 Base Score 7.3 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H).
First Time appeared Oracle
Oracle siebel Crm Deployment
CPEs cpe:2.3:a:oracle:siebel_crm_deployment:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Deployment
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H'}


Subscriptions

Oracle Siebel Crm Deployment
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:17:36.626Z

Reserved: 2026-08-31T15:40:57.343Z

Link: CVE-2026-83155

cve-icon Vulnrichment

Updated: 2026-09-17T14:22:51.391Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:26.307

Modified: 2026-09-17T16:18:05.570

Link: CVE-2026-83155

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T10:00:09Z

Weaknesses