Description
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Siebel Management Console). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data as well as unauthorized update, insert or delete access to some of Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data access and modification
Action: Patch Immediately
AI Analysis

Impact

This vulnerability resides in the Siebel Management Console component of Oracle Siebel CRM Deployment. A low-privileged attacker who can reach the system over HTTP can exploit insufficient access control, enabling the attacker to read confidential data and to update, insert or delete data. The weakness is an improper access control flaw that directly compromises confidentiality and integrity.

Affected Systems

The affected product is Oracle Siebel CRM Deployment, specifically its Siebel Management Console component. Oracle lists supported versions 17.0 through 26.7 as vulnerable.

Risk and Exploitability

The CVSS v3.1 base score of 7.1 indicates a moderate-to-high severity. Although the EPSS score is less than 1%, implying a low likelihood of exploitation at the time of analysis, the impact of successful exploitation is significant, exposing critical data and allowing unauthorized modification. The vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector is network-based HTTP access to the Siebel Management Console, requiring only low privileges to succeed.

Generated by OpenCVE AI on September 20, 2026 at 09:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Oracle patch for Oracle Siebel CRM Deployment referenced at https://www.oracle.com/security-alerts/cspusep2026.html
  • Restrict HTTP access to the Siebel Management Console by implementing firewall rules or VPN to limit traffic to trusted hosts
  • Review and enforce role-based access controls in the Siebel Management Console and monitor for unauthorized data operations

Generated by OpenCVE AI on September 20, 2026 at 09:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Title Siebel CRM Deployment: Unauthorized Access via Management Console

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Low‑Privilege HTTP in Siebel CRM Deployment
Weaknesses CWE-285

Thu, 17 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Low‑Privilege HTTP in Siebel CRM Deployment
Weaknesses CWE-284
CWE-285

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Siebel Management Console). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data as well as unauthorized update, insert or delete access to some of Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle siebel Crm Deployment
CPEs cpe:2.3:a:oracle:siebel_crm_deployment:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Deployment
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Oracle Siebel Crm Deployment
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:13:17.706Z

Reserved: 2026-08-31T15:40:57.348Z

Link: CVE-2026-83230

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:34.850

Modified: 2026-09-17T16:18:10.780

Link: CVE-2026-83230

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T09:30:18Z

Weaknesses