Junglewise Threat Intelligence

CVE-2026-83143: Oracle Siebel CRM eDetailing CSRF or click-jacking vulnerability

CVE-2026-83143 · Severity: high · CVSS 8.1 · Published 2026-09-15

Technologies: Oracle Siebel CRM. Vendors: Oracle.

Executive brief

A vulnerability in Oracle Siebel CRM's Life Sciences product (eDetailing component) allows unauthenticated attackers to perform unauthorized modifications to critical business data via a network-based attack. The flaw requires tricking a user into clicking a malicious link or visiting a crafted webpage, but once triggered, an attacker can read, modify, or delete sensitive customer and sales information managed in Siebel.

Technical details

This vulnerability in the eDetailing component of Oracle Siebel CRM is easily exploitable and requires no authentication to initiate. The attack vector is network-based via HTTP and relies on user interaction (social engineering or click-jacking). The vulnerability allows attackers to achieve both confidentiality and integrity impacts—specifically unauthorized creation, deletion, or modification of critical data within Siebel Apps - Life Sciences. Affected versions range from 17.0 to 26.7. The CVSS 3.1 score of 8.1 reflects the high-impact nature of data manipulation and unauthorized access, though availability is not impacted.

Affected products

  • Oracle Siebel CRM 17.0-26.7

Timeline

  • 2026-09-15: disclosed

References

Related threats