Junglewise Threat Intelligence

CVE-2026-83074: Oracle Siebel CRM unauthorized access in Cloud Manager

CVE-2026-83074 · Severity: high · CVSS 8.6 · Published 2026-09-15

Technologies: Oracle Siebel CRM. Vendors: Oracle.

Executive brief

Oracle Siebel CRM is a customer relationship management platform used by enterprises to manage customer interactions and business data. This vulnerability allows an attacker to access Siebel CRM without credentials via SSH, gaining unauthorized access to sensitive customer and business data stored in the system. The breach could expose confidential customer information and operational records across all connected Siebel CRM instances.

Technical details

This is an authentication bypass vulnerability in the Siebel Cloud Manager component of Oracle Siebel CRM. The vulnerability can be exploited by an unauthenticated attacker over the network via SSH without requiring user interaction or special privileges. The flaw allows attackers to gain unauthorized access to critical data and complete access to all accessible Siebel CRM Cloud Applications data. The scope is rated as changed, meaning successful exploitation may impact additional Oracle products beyond Siebel CRM itself. Affected versions range from 22.3 to 26.7. Oracle has released security patches to address this issue.

Affected products

  • Oracle Siebel CRM 22.3-26.7

Timeline

  • 2026-09-15: disclosed

References

Related threats