Description
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data as well as unauthorized update, insert or delete access to some of Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
Published: 2026-09-15
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access
Action: Immediate Patch
AI Analysis

Impact

The bug resides in the Server Infrastructure component of the Siebel CRM Deployment product. An unauthenticated attacker who can reach the system over HTTP can exploit the vulnerability to obtain unauthorized access to critical data or to gain full read or modify permissions on all data accessible through the deployment. The impact includes confidentiality breaches and integrity violations, potentially allowing the attacker to insert, modify or delete records.

Affected Systems

Oracle Siebel CRM Deployment versions 17.0 through 26.7 are affected. The product is a platform for managing customer relationships, and all deployments running a version in this range are at risk unless updated.

Risk and Exploitability

The vulnerability was scored 8.2 on CVSS v3.1, indicating high severity. EPSS indicates a probability of exploitation of less than 1 %, and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not actively exploited in the wild yet. The attack vector is inferred to be an unauthenticated network request via HTTP; the attacker does not need to authenticate or bypass any authorization controls to exploit the flaw. Given the high confidentiality impact and the availability of a straightforward HTTP request, the risk remains significant for exposed deployments.

Generated by OpenCVE AI on September 20, 2026 at 08:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for Siebel CRM Deployment covering versions 17.0 through 26.7 as soon as it becomes available.
  • Limit HTTP access to the Siebel CRM Deployment servers by using firewalls or VPNs to restrict connections to trusted IP addresses.
  • Enable detailed audit logging on the Siebel CRM Deployment and regularly review logs for unauthorized data modification attempts; consider implementing additional role‑based access controls if not already in place.

Generated by OpenCVE AI on September 20, 2026 at 08:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Title Oracle Siebel CRM Deployment Unauthenticated HTTP Data Disclosure
Weaknesses CWE-200
CWE-284

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Access in Oracle Siebel CRM Deployment Allows Data Compromise
Weaknesses CWE-200
CWE-284

Wed, 16 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Access in Oracle Siebel CRM Deployment Allows Data Compromise
Weaknesses CWE-200
CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data as well as unauthorized update, insert or delete access to some of Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle siebel Crm Deployment
CPEs cpe:2.3:a:oracle:siebel_crm_deployment:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Deployment
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Oracle Siebel Crm Deployment
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-21T16:44:15.435Z

Reserved: 2026-08-31T15:40:57.347Z

Link: CVE-2026-83215

cve-icon Vulnrichment

Updated: 2026-09-21T16:44:10.368Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:33.183

Modified: 2026-09-21T17:19:06.703

Link: CVE-2026-83215

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T09:00:13Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control