Junglewise Threat Intelligence

CVE-2026-83085: Oracle Siebel CRM Cloud Applications authentication bypass in Siebel Cloud Manager

CVE-2026-83085 · Severity: high · CVSS 8.2 · Published 2026-09-15

Technologies: Oracle Siebel CRM Cloud Applications, Oracle Siebel CRM. Vendors: Oracle.

Executive brief

Oracle Siebel CRM Cloud Applications is a cloud-based customer relationship management platform used to manage customer interactions and business data. A low-privilege attacker with physical access to the network segment hosting Siebel CRM can compromise the system and gain full access to sensitive customer data, modify or delete records, and disrupt service availability. The vulnerability potentially affects other connected products beyond Siebel CRM itself.

Technical details

This vulnerability in the Siebel Cloud Manager component allows a low-privileged attacker with adjacent network access (physical communication segment) to exploit easily configurable conditions and bypass authentication controls. The attack requires low privileges and no user interaction, enabling unauthorized access to all accessible data in Siebel CRM Cloud Applications, as well as the ability to modify, insert, or delete data and cause partial denial of service. The vulnerability has a scope change, meaning successful exploitation can impact additional products connected to the affected Siebel deployment. The issue affects versions 22.3 through 26.7, and patches should be available through Oracle's standard security update channels.

Affected products

  • Oracle Siebel CRM Cloud Applications 22.3-26.7

Timeline

  • 2026-09-15: disclosed

References

Related threats