Description
Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Configuration Tools). Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability allows low privileged attacker with network access via SQL to compromise Siebel CRM Development. Successful attacks of this vulnerability can result in takeover of Siebel CRM Development. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Application Takeover
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the Configuration Tools component of Oracle Siebel CRM Development and permits a low‑privileged attacker with network access to exploit a SQL‑related flaw, resulting in full compromise of the application. This impact spans confidentiality, integrity, and availability as reflected in the CVSS score of 7.5. The weakness is a Broken Access Control flaw, identified as CWE-284, and the description indicates that the exploitation can lead to takeover of the Siebel CRM Development environment.

Affected Systems

Oracle Siebel CRM Development versions 17.0 through 26.7 are affected, specifically the Configuration Tools component. Low‑privileged users on the network can reach the vulnerable SQL interface.

Risk and Exploitability

The CVSS base score of 7.5 indicates a high severity, yet the EPSS score of less than 1% suggests that exploitation opportunities are currently rare. The vulnerability is not listed in the CISA KEV catalog, implying no known widespread exploitation. The likely attack vector is via a remote SQL interface that the attacker can reach over the network, and the success of the attack requires only low privileges, elevating the risk for systems with inadequate access control.

Generated by OpenCVE AI on September 20, 2026 at 09:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle Siebel CRM Development security patch as soon as it is released.
  • Restrict network access to the database endpoints used by Siebel CRM Development, allowing connections only from trusted hosts.
  • Enforce strict role‑based access controls, limiting low‑privileged users to necessary actions within Siebel CRM Development.

Generated by OpenCVE AI on September 20, 2026 at 09:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Title SQL Vulnerability in Siebel CRM Development Allows Low-Privileged Application Takeover

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title SQL Injection Leading to Full Application Takeover in Oracle Siebel CRM Development
Weaknesses CWE-89

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Title SQL Injection Leading to Full Application Takeover in Oracle Siebel CRM Development
Weaknesses CWE-89

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Configuration Tools). Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability allows low privileged attacker with network access via SQL to compromise Siebel CRM Development. Successful attacks of this vulnerability can result in takeover of Siebel CRM Development. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle siebel Crm Development
CPEs cpe:2.3:a:oracle:siebel_crm_development:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Development
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Siebel Crm Development
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:15:41.379Z

Reserved: 2026-08-31T15:40:57.345Z

Link: CVE-2026-83182

cve-icon Vulnrichment

Updated: 2026-09-17T14:58:27.772Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:29.357

Modified: 2026-09-17T16:18:07.880

Link: CVE-2026-83182

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T10:00:09Z

Weaknesses