Description
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows high privileged attacker with network access via TCP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Privilege Escalation and Full System Compromise
Action: Patch Now
AI Analysis

Impact

This vulnerability resides in the Server Infrastructure component of Oracle Siebel CRM Deployment. An attacker with network access via TCP can exploit a flaw that enables the bypass or override of normal access controls, allowing the attacker to elevate privileges and ultimately take full control of the application. Successful exploitation results in complete compromise, impacting confidentiality, integrity, and availability of all data and services managed by the CRM system.

Affected Systems

Affected vendor: Oracle Corporation, product: Siebel CRM Deployment. Versions 17.0 through 26.7 are impacted. The vulnerability is present across all build variants of this product range.

Risk and Exploitability

The CVSS v3.1 base score of 7.2 indicates a high severity with impacts to confidentiality, integrity and availability. The EPSS score of less than 1% suggests that real‑world exploitation is currently rare, and the vulnerability is not listed in the CISA KEV catalog. However, the attack vector is a TCP connection that a remote attacker can establish, so a threat actor could attempt this attack. Once the flaw is exploited the attacker can fully takeover the Siebel CRM Deployment instance.

Generated by OpenCVE AI on September 20, 2026 at 09:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch or upgrade to a fixed version for Siebel CRM Deployment.
  • Restrict inbound TCP access to the Siebel CRM Deployment endpoints to trusted networks or IP ranges via firewall or ACLs.
  • Implement monitoring and logging on the Siebel CRM Deployment to detect abnormal privilege escalation attempts or unauthorized access patterns.

Generated by OpenCVE AI on September 20, 2026 at 09:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Title High‑Severity Remote Privilege Escalation Vulnerability in Oracle Siebel CRM Deployment

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Siebel CRM Deployment Privilege Escalation via TCP Network Access
Weaknesses CWE-284

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Title Siebel CRM Deployment Privilege Escalation via TCP Network Access
Weaknesses CWE-269
CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows high privileged attacker with network access via TCP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle siebel Crm Deployment
CPEs cpe:2.3:a:oracle:siebel_crm_deployment:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Deployment
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Siebel Crm Deployment
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:10:41.918Z

Reserved: 2026-08-31T15:40:57.345Z

Link: CVE-2026-83195

cve-icon Vulnrichment

Updated: 2026-09-17T13:01:42.755Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:30.940

Modified: 2026-09-17T14:17:36.160

Link: CVE-2026-83195

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T09:15:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management