Description
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Deployment executes to compromise Siebel CRM Deployment. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Compromise of Siebel CRM Deployment
Action: Assess Impact
AI Analysis

Impact

The vulnerability resides in the Server Infrastructure component of Oracle Siebel CRM Deployment and allows a low‑privileged attacker who can log on to the underlying infrastructure to execute code paths that can result in a full takeover of the Siebel CRM Deployment service. Successful exploitation for this vulnerability can lead to complete loss of confidentiality, integrity, and availability of the application, enabling the attacker to control its operation.

Affected Systems

Oracle Siebel CRM Deployment versions 17.0 through 26.7 are affected. Organisations using these releases must confirm their version and plan to apply a vendor‑issued fix if one becomes available.

Risk and Exploitability

The CVSS 3.1 base score of 7.3 indicates substantial impact, while the EPSS of less than 1% suggests that exploitation is unlikely at present but remains possible. The vulnerability is not listed in the CISA KEV catalog. The attack requires local access (AV:L) and human interaction from a user other than the attacker, which implies a moderate to high risk for environments that do not restrict local logon privileges or monitor for suspicious activity.

Generated by OpenCVE AI on September 20, 2026 at 09:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Verify whether Oracle has released a patch or upgrade that addresses this vulnerability and apply it or upgrade beyond version 26.7 as soon as it is available.
  • Enforce least‑privilege on local accounts that have logon rights to the Siebel CRM Deployment servers, limiting access to only trusted personnel and disabling unnecessary local console or management interfaces.
  • Monitor log files for unauthorized or anomalous local activity and configure alerts for suspicious logon events to reduce the chance of successful human interaction required for exploitation.

Generated by OpenCVE AI on September 20, 2026 at 09:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Exploit Allows Siebel CRM Deployment Takeover

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege Logon Allows Full Compromise of Siebel CRM Deployment
Weaknesses CWE-284

Thu, 17 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege Logon Allows Full Compromise of Siebel CRM Deployment
Weaknesses CWE-269
CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Deployment executes to compromise Siebel CRM Deployment. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle siebel Crm Deployment
CPEs cpe:2.3:a:oracle:siebel_crm_deployment:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Deployment
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Siebel Crm Deployment
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:00:16.171Z

Reserved: 2026-08-31T15:40:57.345Z

Link: CVE-2026-83190

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:30.397

Modified: 2026-09-17T14:17:35.497

Link: CVE-2026-83190

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T09:45:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management