Description
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote takeover of Siebel CRM Deployment
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the server infrastructure component of Oracle Siebel CRM Deployment and permits an unauthenticated attacker with TCP network access to compromise the system. The flaw enables full control, resulting in loss of confidentiality, integrity, and availability of data and application functions, as reflected in the CVSS v3.1 vector with high complexity and no required privileges. Successful exploitation can lead to a complete takeover of the deployment.

Affected Systems

Oracle Corporation’s Siebel CRM Deployment product is affected, specifically versions 17.0 through 26.7 of the software. Systems running any of these revisions are at risk if not updated.

Risk and Exploitability

The base CVSS score of 8.1 indicates high severity, but the current EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Attackers require only network connectivity to the vulnerable service, no special credentials or user interaction, and are able to forge requests to the TCP port that hosts the server infrastructure.

Generated by OpenCVE AI on September 18, 2026 at 20:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest supported version of Oracle Siebel CRM Deployment (above 26.7) or apply the vendor’s patch as soon as it is available.
  • Restrict network access to the Siebel CRM Deployment service by configuring firewalls or segmentation to allow traffic only from trusted IP ranges.
  • Enable and monitor logging for authentication and connection attempts to the Server Infrastructure port to detect abnormal activity.

Generated by OpenCVE AI on September 18, 2026 at 20:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Access Allows Complete Compromise of Oracle Siebel CRM Deployment

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Access Allows Complete Compromise of Oracle Siebel CRM Deployment
Weaknesses CWE-200
CWE-287

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle siebel Crm Deployment
CPEs cpe:2.3:a:oracle:siebel_crm_deployment:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Deployment
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Siebel Crm Deployment
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:10:42.556Z

Reserved: 2026-08-31T15:40:57.345Z

Link: CVE-2026-83191

cve-icon Vulnrichment

Updated: 2026-09-17T13:01:52.343Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:30.503

Modified: 2026-09-17T14:17:35.627

Link: CVE-2026-83191

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:30:16Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-269

    Improper Privilege Management

  • CWE-287

    Improper Authentication