Description
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Deployment accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-09-15
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data modification and potential full data access via unauthenticated HTTP access
Action: Immediate Patch
AI Analysis

Impact

A flaw in the Server Infrastructure component of Oracle Siebel CRM Deployment allows an unauthenticated attacker with network access over HTTP to create, delete, or modify critical data. The bug was scored CVSS 9.1 with high confidentiality and integrity impact, and the CVSS vector indicates that no user interaction or privileges are required for exploitation.

Affected Systems

Oracle Siebel CRM Deployment versions 17.0 through 26.7 are affected. The vulnerability exists in the Siebel CRM Deployment product and is specific to the Server Infrastructure component.

Risk and Exploitability

The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low exploitation probability at present. However, the high CVSS score and the fact that an unauthenticated network attacker can gain full control over deployment data create a significant risk. The attack vector is via HTTP and requires no authentication, so any host exposed to the network could be compromised if the patch is not applied.

Generated by OpenCVE AI on September 16, 2026 at 21:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch that addresses CVE-2026-83202 to all affected Siebel CRM Deployment instances
  • Restrict HTTP access to Siebel CRM Deployment so that only trusted, internal networks can reach the service
  • Enforce strong authentication and limit administrative privileges after patching
  • Monitor log files for anomalous creation, deletion, or modification activity to detect potential exploitation

Generated by OpenCVE AI on September 16, 2026 at 21:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
CWE-306

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Deployment accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle siebel Crm Deployment
CPEs cpe:2.3:a:oracle:siebel_crm_deployment:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Deployment
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Siebel Crm Deployment
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T22:54:41.421Z

Reserved: 2026-08-31T15:40:57.346Z

Link: CVE-2026-83202

cve-icon Vulnrichment

Updated: 2026-09-15T22:47:23.738Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:31.763

Modified: 2026-09-16T19:42:12.090

Link: CVE-2026-83202

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T22:00:08Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function