Junglewise Threat Intelligence

CVE-2026-83087: Oracle Siebel CRM unauthorized data access in Cloud Manager

CVE-2026-83087 · Severity: high · CVSS 8.2 · Published 2026-09-15

Technologies: Oracle Siebel CRM Cloud Applications. Vendors: Oracle.

Executive brief

Oracle Siebel CRM Cloud Manager is a system used to manage Siebel customer relationship management deployments in the cloud. A vulnerability in this component allows low-privileged authenticated users with network access to gain unauthorized read, create, modify, or delete access to sensitive business data stored in Siebel CRM systems. Successful exploitation could compromise confidentiality and integrity of critical customer information and CRM records across affected deployments.

Technical details

The vulnerability is a difficult-to-exploit access control flaw in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications (versions 22.3–26.7) that requires network access via HTTP and a low-privileged account. An authenticated attacker can bypass authorization controls to read, create, modify, or delete critical data in Siebel CRM Cloud Applications and potentially impact other connected products due to scope change. The vulnerability results in high confidentiality and integrity impact without affecting availability (CVSS 3.1 score: 8.2). Patches are available from Oracle as of the published date.

Affected products

  • Oracle Siebel CRM Cloud Applications 22.3–26.7

Timeline

  • 2026-09-15: disclosed

References

Related threats