Description
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution and full system takeover
Action: Apply patch
AI Analysis

Impact

A vulnerability classified as CWE-284 exists in Oracle Siebel CRM Deployment that permits a low‑privileged attacker with network access via HTTP to compromise the system. Successful exploitation can lead to complete takeover, compromising confidentiality, integrity and availability of the entire application. The weakness is a flaw in the server infrastructure that allows unauthorized privileged actions when HTTP requests are received.

Affected Systems

The affected vendor is Oracle Corporation, product Siebel CRM Deployment. Versions 17.0 through 26.7 are impacted. Only deployments of these versions are at risk, while newer releases are not listed as vulnerable.

Risk and Exploitability

The vulnerability has a CVSS 3.1 base score of 7.5, reflecting high overall severity. The EPSS score is slightly below 1%, indicating a low but non‑zero likelihood that the flaw will be targeted in the wild. It is not listed in the CISA KEV catalog. The likely attack vector is a network‑based HTTP request, with a low privileged attacker able to trigger the exploit and gain system‑level control.

Generated by OpenCVE AI on September 18, 2026 at 19:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Siebel CRM Deployment to the latest version or apply the Oracle vendor patch for CVE-2026-83226
  • Restrict external HTTP access to the CRM service using firewall rules or a VPN tunnel to limit exposure to trusted networks
  • Enforce the principle of least privilege on the server process and review application permissions to prevent misuse of elevated rights
  • Enable and enforce multi‑factor authentication for all deployment
  • Monitor system logs for anomalous authentication or request patterns to detect early signs of exploitation

Generated by OpenCVE AI on September 18, 2026 at 19:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege Network Attack Compromise of Siebel CRM Deployment

Wed, 16 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege Network Attack Compromise of Siebel CRM Deployment
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle siebel Crm Deployment
CPEs cpe:2.3:a:oracle:siebel_crm_deployment:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Deployment
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Siebel Crm Deployment
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:13:34.421Z

Reserved: 2026-08-31T15:40:57.347Z

Link: CVE-2026-83226

cve-icon Vulnrichment

Updated: 2026-09-17T14:58:16.071Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:34.403

Modified: 2026-09-17T16:18:10.410

Link: CVE-2026-83226

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:15:14Z

Weaknesses