Junglewise Threat Intelligence

CVE-2026-83145: Oracle Siebel CRM Order Management cross-site request forgery

CVE-2026-83145 · Severity: high · CVSS 8.7 · Published 2026-09-15

Technologies: Oracle Siebel CRM. Vendors: Oracle.

Executive brief

Oracle Siebel CRM's Order Management component is vulnerable to a cross-site attack that allows an attacker with network access to trick a logged-in user into modifying or deleting critical customer order data. A successful exploit could result in unauthorized changes to order information, customer data loss, or complete data compromise, impacting business operations and customer trust.

Technical details

This vulnerability in the Order Management component of Oracle Siebel CRM (versions 17.0–26.7) is easily exploitable via HTTP by a low-privileged network attacker with user interaction. The vulnerability has a scope change, meaning attacks on the Order Management component can impact other Siebel CRM products. Successful exploitation grants unauthorized access to create, delete, or modify critical data, or read all accessible data within the Order Management system. The vulnerability requires user interaction (UI:R in the CVSS vector) and a low authentication requirement (PR:L), making it practical to exploit in multi-user environments. Patch availability from Oracle should be monitored.

Affected products

  • Oracle Siebel CRM 17.0-26.7

Timeline

  • 2026-09-15: disclosed

References

Related threats