Description
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. While the vulnerability is in Siebel CRM Deployment, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-09-15
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Privilege Escalation
Action: Patch Now
AI Analysis

Impact

The vulnerability resides in the Server Infrastructure component of Oracle Siebel CRM Deployment. A high‑privileged attacker who can reach the system over HTTP can exploit this flaw to gain complete control of the deployment, potentially compromising confidentiality, integrity, and availability. The flaw is a privilege escalation weakness that enables takeover of the deployment environment and may affect additional products due to scope change.

Affected Systems

Oracle Siebel CRM Deployment, versions 17.0 through 26.7, are affected. All supported releases in this range are vulnerable whenever the Server Infrastructure component is exposed to network traffic.

Risk and Exploitability

CVSS 3.1 base score of 9.1 classifies the issue as critical. EPSS < 1% indicates a low current exploitation probability, but the lack of KEV listing does not reduce overall risk. Exploitation requires network access via HTTP and a high‑privilege account, after which the attacker can fully compromise the system. The likely attack vector is over HTTP traffic to the deployment server.

Generated by OpenCVE AI on September 17, 2026 at 03:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Siebel CRM Deployment security patch
  • Restrict HTTP access to the Siebel CRM Deployment server with firewall rules, VPNs, or network segmentation
  • Enforce strong authentication and the principle of least privilege for all accounts accessing the deployment system
  • Monitor authentication logs and HTTP traffic for suspicious activity or privilege escalation attempts

Generated by OpenCVE AI on September 17, 2026 at 03:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Title High-Privilege HTTP Exploit Enables Takeover of Oracle Siebel CRM Deployment
Weaknesses CWE-264

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. While the vulnerability is in Siebel CRM Deployment, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle siebel Crm Deployment
CPEs cpe:2.3:a:oracle:siebel_crm_deployment:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Deployment
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Siebel Crm Deployment
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T20:04:17.867Z

Reserved: 2026-08-31T15:40:57.345Z

Link: CVE-2026-83196

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:31.057

Modified: 2026-09-16T19:36:43.087

Link: CVE-2026-83196

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T03:45:20Z

Weaknesses