Junglewise Threat Intelligence

CVE-2026-83144: Oracle Siebel Apps Customer Order Management privilege escalation in Order Management

CVE-2026-83144 · Severity: high · CVSS 8.7 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Siebel Apps Customer Order Management is a business software component used to manage customer orders and sales workflows. A vulnerability allows a low-privilege user with network access to modify or delete critical order data and access sensitive customer information through a cross-site request forgery (CSRF) attack, requiring victim interaction. Exploitation could lead to unauthorized changes to orders, customer data loss, or exposure of confidential business information.

Technical details

This is a privilege escalation vulnerability in Oracle Siebel Apps Customer Order Management (Order Management component) affecting versions 17.0 through 26.7. The vulnerability is easily exploitable over HTTP by a low-privileged attacker with network access and requires user interaction from a different person (indicating CSRF or similar social engineering vector). The scope is marked as changed, meaning exploitation impacts resources beyond the vulnerable component itself. Successful exploitation allows unauthorized creation, deletion, or modification of critical order data and unauthorized access to sensitive customer information. The vulnerability has been publicly disclosed but is not reported as actively exploited in the wild. Patches should be obtained from Oracle's September 2026 security advisory.

Affected products

  • Oracle Siebel Apps - Customer Order Management 17.0 through 26.7

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: advisory: Oracle Critical Patch Update September 2026

References