Description
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution
Action: Immediate Patch
AI Analysis

Impact

Oracle Siebel CRM Deployment is vulnerable to a flaw in its Server Infrastructure component that allows an attacker with low privileges and network access via HTTP to execute arbitrary code and assume full control of the deployment. The flaw corresponds to an unauthorized access weakness, enabling the attacker to elevate privileges and compromise confidentiality, integrity and availability. The reported CVSS score of 8.8 indicates severe impact and the vector shows that no authentication is required beyond low privileged access.

Affected Systems

Oracle Siebel CRM Deployment, versions 17.0 through 26.7, is affected. Installations outside this range are not listed as vulnerable.

Risk and Exploitability

The likelihood of exploitation is currently low, with an EPSS score of less than 1%, and the vulnerability is not tracked in CISA KEV. Nonetheless the high CVSS impact and ease of exploitation via the public HTTP interface mean that a compromised deployment would allow a full data breach and service disruption. Attackers can achieve confidentiality, integrity, and availability compromise once the flaw is used.

Generated by OpenCVE AI on September 20, 2026 at 09:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest vendor patch or upgrade to a version newer than 26.7
  • Restrict HTTP access to the Siebel CRM Deployment servers to trusted IP ranges or a VPN tunnel
  • Monitor administrative interfaces and log traffic for anomalous activity

Generated by OpenCVE AI on September 20, 2026 at 09:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Title Siebel CRM Deployment Low Privilege HTTP Exploit Enabling System Takeover

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Remote Exploitation Leading to Deployment Takeover in Oracle Siebel CRM via HTTP
Weaknesses CWE-269

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
Title Remote Exploitation Leading to Deployment Takeover in Oracle Siebel CRM via HTTP
Weaknesses CWE-269
CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle siebel Crm Deployment
CPEs cpe:2.3:a:oracle:siebel_crm_deployment:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Deployment
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Siebel Crm Deployment
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:15:58.910Z

Reserved: 2026-08-31T15:40:57.344Z

Link: CVE-2026-83180

cve-icon Vulnrichment

Updated: 2026-09-17T14:58:28.770Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:29.130

Modified: 2026-09-17T16:18:07.593

Link: CVE-2026-83180

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T09:15:17Z

Weaknesses