Description
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. While the vulnerability is in Siebel CRM Deployment, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-09-15
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: High-Privilege Takeover
Action: Patch Now
AI Analysis

Impact

The vulnerability resides in the Server Infrastructure component of Oracle Siebel CRM Deployment. A high‑privileged attacker who can reach the system over HTTP can exploit this flaw to gain complete control of the deployment, potentially compromising confidentiality, integrity, and availability. The flaw is a privilege escalation weakness that enables takeover of the deployment environment and may affect additional products due to scope change.

Affected Systems

Oracle Siebel CRM Deployment, versions 17.0 through 26.7, are affected. All supported releases in this range are vulnerable whenever the Server Infrastructure component is exposed to network traffic.

Risk and Exploitability

CVSS 3.1 base score of 9.1 classifies the issue as critical. EPSS < 1% indicates a low current exploitation probability, but the lack of KEV listing does not reduce overall risk. Exploitation requires network access via HTTP and a high‑privilege account, after which the attacker can fully compromise the system. The likely attack vector is over HTTP traffic to the deployment server.

Generated by OpenCVE AI on September 18, 2026 at 20:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle Siebel CRM Deployment security patch
  • Restrict HTTP access to the Siebel CRM Deployment server with firewall rules, VPNs, or network segmentation
  • Enforce strong authentication and the principle of least privilege for all accounts accessing the deployment system
  • Monitor authentication logs and HTTP traffic for suspicious activity or privilege escalation attempts

Generated by OpenCVE AI on September 18, 2026 at 20:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title High-Privilege HTTP Exploit Enables Takeover of Oracle Siebel CRM Deployment

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Title High-Privilege HTTP Exploit Enables Takeover of Oracle Siebel CRM Deployment
Weaknesses CWE-264

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. While the vulnerability is in Siebel CRM Deployment, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle siebel Crm Deployment
CPEs cpe:2.3:a:oracle:siebel_crm_deployment:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Deployment
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Siebel Crm Deployment
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:10:41.724Z

Reserved: 2026-08-31T15:40:57.345Z

Link: CVE-2026-83196

cve-icon Vulnrichment

Updated: 2026-09-17T13:01:39.145Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:31.057

Modified: 2026-09-17T14:17:36.290

Link: CVE-2026-83196

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:15:14Z

Weaknesses