Description
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Deployment executes to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation leading to full compromise of Oracle Siebel CRM Deployment
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the Server Infrastructure component of Oracle Siebel CRM Deployment. An attacker who can logon locally with low privileges can exploit this weakness to take over the deployment. The flaw, characterized as an improper access control issue (CWE-269), leads to full confidentiality, integrity, and availability loss once compromised.

Affected Systems

Oracle Corporation’s Siebel CRM Deployment product is impacted. Versions from 17.0 through 26.7 contain the flaw. Any environment running these products without the vendor‑issued fix is vulnerable.

Risk and Exploitability

The CVSS v3.1 base score of 7.8 reflects significant risk. The EPSS score is below 1%, indicating a low but non‑zero likelihood of exploitation in the wild, and the vulnerability is not currently listed in CISA KEV. Local attackers with logon rights who can execute code on the infrastructure are the primary threat vector, and they can achieve full control of the deployment with no user interaction.

Generated by OpenCVE AI on September 20, 2026 at 08:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Oracle patch that addresses CVE-2026-83211 for all affected versions (17.0–26.7).
  • Restrict local user accounts to the minimum privileges required for their role and remove any unnecessary logon rights.
  • Enable and regularly review audit logs to detect suspicious activity that could indicate exploitation attempts.

Generated by OpenCVE AI on September 20, 2026 at 08:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Leading to Full Compromise of Oracle Siebel CRM Deployment
Weaknesses CWE-284

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269

Wed, 16 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Leading to Full Compromise of Oracle Siebel CRM Deployment
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Deployment executes to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle siebel Crm Deployment
CPEs cpe:2.3:a:oracle:siebel_crm_deployment:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Deployment
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Siebel Crm Deployment
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:00:15.859Z

Reserved: 2026-08-31T15:40:57.347Z

Link: CVE-2026-83211

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:32.750

Modified: 2026-09-17T14:17:36.417

Link: CVE-2026-83211

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T09:00:13Z

Weaknesses
  • CWE-269

    Improper Privilege Management