Junglewise Threat Intelligence

CVE-2026-82992: Oracle Siebel CRM privilege escalation in Installation

CVE-2026-82992 · Severity: high · CVSS 7.8 · Published 2026-09-15

Executive brief

Oracle Siebel CRM is an enterprise customer relationship management system used by organizations to manage customer interactions and sales operations. A privilege escalation vulnerability in the installation component allows a low-privileged user with local access to gain complete control of the Siebel CRM system, potentially exposing customer data and disrupting business operations.

Technical details

This is a local privilege escalation vulnerability in the Installation component of Oracle Siebel CRM Deployment affecting versions 17.0 through 26.7. The vulnerability is easily exploitable and requires low privilege logon access to the infrastructure hosting Siebel CRM Deployment. An attacker with these prerequisites can achieve complete system compromise, resulting in full control over the Siebel CRM Deployment with impacts to confidentiality, integrity, and availability. The attack vector is local, requires user interaction to be present on the system, and does not require elevated privileges to execute.

Affected products

  • Oracle Siebel CRM Deployment 17.0-26.7

Timeline

  • 2026-09-15: disclosed

References

Related threats