Executive brief
Siebel CRM Cloud Applications, a customer relationship management system used by enterprises to manage customer interactions and business data, contains a vulnerability in its Siebel Cloud Manager component. An attacker with physical access to the network segment connected to the system can bypass authentication and gain unauthorized access to create, modify, or delete critical customer and business data without any credentials.
Technical details
This is an unauthenticated remote access vulnerability in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications versions 22.3 through 26.7. The vulnerability requires physical access to the adjacent communication segment (network-adjacent attack vector), but no authentication credentials or user interaction. Successful exploitation allows an attacker to compromise the confidentiality and integrity of all accessible data within the Siebel CRM Cloud Applications, including creation, deletion, or modification of critical records. The attack has low complexity and does not affect system availability. Oracle has assigned this issue CVE-2026-83073 with a CVSS 3.1 Base Score of 8.1.
Affected products
- Oracle Siebel CRM Cloud Applications 22.3-26.7
Timeline
- 2026-09-15: disclosed