Description
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Siebel Remote). Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Takeover
Action: Apply Patch
AI Analysis

Impact

The vulnerability lies in the Siebel Remote component of Oracle Siebel CRM Deployment. It allows an attacker with low privileges and network connectivity via HTTP to exploit a flaw that ultimately grants the attacker the ability to compromise the deployment. Successful exploitation results in full takeover and loss of confidentiality, integrity and availability of all data and services managed by the system. The weakness is a form of improper access control.

Affected Systems

Oracle Corporation's Siebel CRM Deployment product, specifically versions 17.0 through 26.7, is affected.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity, while the EPSS score of less than 1% suggests that exploitation attempts are rare and the vulnerability is not listed in CISA KEV. The attack vector most likely involves a crafted HTTP request sent to the Siebel Remote endpoint from a low‑privileged host. Although the flaw is difficult to exploit, once triggered the attacker can control the deployment and all underlying data.

Generated by OpenCVE AI on September 18, 2026 at 19:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied update for affected Siebel CRM Deployment versions as soon as it is released.
  • If a patch is not yet available, restrict HTTP access to the deployment behind a firewall or NAT, allowing only trusted networks to reach it.
  • Enable detailed audit logging and monitor for anomalous authentication or configuration changes, and enforce strict access control around the Siebel Remote component.

Generated by OpenCVE AI on September 18, 2026 at 19:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Exploit Enables Remote Takeover of Oracle Siebel CRM Deployment

Thu, 17 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Exploit Enables Remote Takeover of Oracle Siebel CRM Deployment
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Siebel Remote). Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle siebel Crm Deployment
CPEs cpe:2.3:a:oracle:siebel_crm_deployment:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Deployment
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Siebel Crm Deployment
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:13:49.232Z

Reserved: 2026-08-31T15:40:57.347Z

Link: CVE-2026-83223

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:34.060

Modified: 2026-09-17T16:18:10.150

Link: CVE-2026-83223

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T19:45:13Z

Weaknesses