Junglewise Threat Intelligence

CVE-2026-83196: Oracle Siebel CRM Server Infrastructure privilege escalation

CVE-2026-83196 · Severity: critical · CVSS 9.1 · Published 2026-09-15

Technologies: Oracle Siebel CRM Deployment. Vendors: Oracle.

Executive brief

Oracle Siebel CRM is a customer relationship management platform used to manage sales, service, and marketing operations. A privilege escalation vulnerability in the Server Infrastructure component allows a high-privilege attacker to gain complete control of the system and potentially compromise related systems through scope change, resulting in total loss of confidentiality, integrity, and availability.

Technical details

This is a privilege escalation vulnerability in the Server Infrastructure component of Oracle Siebel CRM Deployment (versions 17.0–26.7). The vulnerability requires an attacker to have high-level privileges and network access via HTTP; no special preconditions or user interaction are needed beyond these. Successful exploitation allows a high-privileged attacker to achieve complete system compromise with scope change, affecting confidentiality, integrity, and availability across Siebel CRM Deployment and potentially related products. The CVSS 3.1 vector (AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H) reflects network accessibility and high complexity with high-privilege requirements. Patch status and further technical details are not publicly available at this time.

Affected products

  • Oracle Siebel CRM Deployment 17.0–26.7

Timeline

  • 2026-09-15: disclosed

References

Related threats