Description
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Migration). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a SQL injection flaw within the Migration component of Oracle Siebel CRM Deployment. An attacker with low privileged access and network connectivity can send crafted SQL input that is not properly sanitized, allowing arbitrary SQL statements to be executed. Successful exploitation results in a full takeover of the application, compromising confidentiality, integrity, and availability. The weakness corresponds to CWE-89, an SQL injection flaw.

Affected Systems

Oracle’s Siebel CRM Deployment product is affected across versions 17.0 through 26.7. The vulnerability is present in the Migration component of these releases.

Risk and Exploitability

The CVSS v3.1 base score of 8.8 indicates a high severity with full impact on confidentiality, integrity, and availability. The EPSS score is below 1%, suggesting a low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. The description indicates the issue resides in the Migration component, which is exposed via network-accessible interfaces. Based on the description, it is inferred that an attacker would send crafted SQL input to this component, causing arbitrary SQL execution and takeover.

Generated by OpenCVE AI on September 22, 2026 at 20:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest official Oracle Siebel CRM Deployment security patch or upgrade to a version beyond 26.7.
  • Restrict network access to the migration component and database interfaces to authorized personnel only, using firewall rules and network segmentation.
  • Enforce strict input validation and use parameterized queries for all database interactions within the Migration component, following safeguards for CWE-89.

Generated by OpenCVE AI on September 22, 2026 at 20:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title SQL Injection in Siebel CRM Deployment Migration Enables Full Takeover

Tue, 22 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284 CWE-89

Sun, 20 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Title SQL Injection in Siebel CRM Deployment Migration Enables Full Takeover

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title SQL Injection in Oracle Siebel CRM Deployment Enables Low-Privilege Takeover
Weaknesses CWE-20
CWE-89

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title SQL Injection in Oracle Siebel CRM Deployment Enables Low-Privilege Takeover
Weaknesses CWE-20
CWE-89

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Migration). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle siebel Crm Deployment
CPEs cpe:2.3:a:oracle:siebel_crm_deployment:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Deployment
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Siebel Crm Deployment
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-22T17:22:19.539Z

Reserved: 2026-08-31T15:40:57.346Z

Link: CVE-2026-83208

cve-icon Vulnrichment

Updated: 2026-09-17T14:58:20.084Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:32.423

Modified: 2026-09-22T18:17:21.923

Link: CVE-2026-83208

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T20:45:16Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')