Junglewise Threat Intelligence

CVE-2026-83182: Oracle Siebel CRM Development privilege escalation in Configuration Tools

CVE-2026-83182 · Severity: high · CVSS 7.5 · Published 2026-09-15

Technologies: Oracle Siebel CRM Development. Vendors: Oracle.

Executive brief

Oracle Siebel CRM Development is a customer relationship management platform used by enterprises to manage sales, marketing, and customer service operations. A vulnerability in the Configuration Tools component allows a low-privileged attacker with network access to exploit SQL functionality and gain complete control of the system, potentially exposing or modifying sensitive customer and business data stored within the CRM.

Technical details

This is a privilege escalation vulnerability affecting Oracle Siebel CRM Development versions 17.0 through 26.7 in the Configuration Tools component. The vulnerability is exploitable via SQL with network access and requires low-level privileges and complex exploitation conditions (high attack complexity). A successful attack allows an attacker to achieve full system compromise with impacts to confidentiality, integrity, and availability. The vulnerability has not been reported as exploited in the wild. Patch status and detailed remediation guidance should be obtained from Oracle security bulletins.

Affected products

  • Oracle Siebel CRM Development 17.0-26.7

Timeline

  • 2026-09-15: disclosed

References

Related threats