Junglewise Threat Intelligence

CVE-2026-83193: Oracle Siebel Apps Life Sciences privilege escalation

CVE-2026-83193 · Severity: high · CVSS 7.3 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Siebel CRM's Life Sciences module is vulnerable to a privilege escalation attack that allows a low-privileged local user to gain full control of the application when manipulated through a social engineering attack. Exploitation requires the attacker to have local system access and trick another user into opening a malicious file or interaction, but if successful, an attacker can compromise confidentiality, integrity, and availability of customer relationship management data and operations.

Technical details

This vulnerability is a local privilege escalation flaw in the Siebel Apps Life Sciences component (versions 17.0–26.7). The attack vector is local with low privileges required and user interaction needed; an attacker with logon access to the infrastructure can craft a malicious interaction that, when clicked or processed by another user, elevates their privileges to compromise the entire application. The vulnerability allows unauthorized access to sensitive business data, modification of customer records, and potential denial of service. Patches for affected versions are likely available through Oracle's security updates.

Affected products

  • Oracle Siebel Apps Life Sciences 17.0–26.7

Timeline

  • 2026-09-15: disclosed

References