Description
Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Integration - Scripting). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Development. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Development as well as unauthorized update, insert or delete access to some of Siebel CRM Development accessible data and unauthorized read access to a subset of Siebel CRM Development accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H).
Published: 2026-09-15
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service and unauthorized data manipulation
Action: Immediate Patch
AI Analysis

Impact

A flaw in the Integration – Scripting component of Oracle’s Siebel CRM Development allows an attacker with low privileges and network access via HTTP to bypass authentication checks and manipulate data or crash the application. The vulnerability arises from improper access control (CWE‑284) and the possibility for unauthorized updates, inserts, deletes, and reads available through the HTTP interface. Successful exploitation can lead to loss of data integrity, availability through repeated crashes, and partial disclosure of sensitive data.

Affected Systems

Oracle Siebel CRM Development versions 17.0 through 26.7 are affected. The flaw is exposed through any deployment that serves integration scripts over an unprotected HTTP channel.

Risk and Exploitability

The vulnerability has a CVSS score of 7.6, indicating high severity with low complexity and low privileges required. The EPSS score of less than 1 % indicates that exploitation is unlikely but still possible. It is not listed in the CISA KEV catalog. Attackers can remotely trigger the flaw via HTTP without user interaction, making it a straightforward low‑effort, high‑impact attack for networks with open access to the affected server.

Generated by OpenCVE AI on September 20, 2026 at 09:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for Siebel CRM Development that addresses the Integration – Scripting flaw.
  • Restrict HTTP access to the Siebel CRM Development server to trusted IP ranges or internal networks only.
  • Ensure that users and roles that run integration scripts are granted only the minimum permissions necessary for their tasks.
  • Monitor application logs for repeated crash events, unexpected script execution, or unauthorized data operations and investigate promptly.

Generated by OpenCVE AI on September 20, 2026 at 09:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Title Siebel CRM Development Integration‑Scripting Vulnerability Enables Low‑Privilege Denial of Service and Unauthorized Data Access

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Manipulation via HTTP in Siebel CRM Integration Scripting
Weaknesses CWE-640

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Manipulation via HTTP in Siebel CRM Integration Scripting
Weaknesses CWE-640

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Integration - Scripting). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Development. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Development as well as unauthorized update, insert or delete access to some of Siebel CRM Development accessible data and unauthorized read access to a subset of Siebel CRM Development accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H).
First Time appeared Oracle
Oracle siebel Crm Development
CPEs cpe:2.3:a:oracle:siebel_crm_development:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Development
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H'}


Subscriptions

Oracle Siebel Crm Development
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:14:19.370Z

Reserved: 2026-08-31T15:40:57.346Z

Link: CVE-2026-83207

cve-icon Vulnrichment

Updated: 2026-09-17T14:22:37.002Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:32.310

Modified: 2026-09-17T16:18:09.590

Link: CVE-2026-83207

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T09:15:17Z

Weaknesses