Junglewise Threat Intelligence

CVE-2026-83197: Oracle Siebel CRM Financial Services authentication bypass in Financial Accounts

CVE-2026-83197 · Severity: critical · CVSS 9.1 · Published 2026-09-15

Technologies: Oracle Siebel CRM. Vendors: Oracle.

Executive brief

Oracle Siebel CRM is an enterprise customer relationship management platform used by financial services firms to manage customer accounts and data. A critical unauthenticated vulnerability in the Financial Accounts component allows remote attackers to access sensitive customer and financial data without credentials, and to crash the service. This could expose confidential financial information and disrupt business operations.

Technical details

An easily exploitable authentication bypass or direct object reference vulnerability exists in the Financial Accounts component of Oracle Siebel CRM's Financial Services application. The flaw is reachable remotely over HTTP without authentication or user interaction required. An attacker with network access can exploit this to read all accessible financial and customer data and trigger denial-of-service conditions (application hang or crash). The vulnerability affects Siebel Apps versions 17.0 through 26.7. Oracle has assigned CVE-2026-83197 with a CVSS 3.1 score of 9.1 reflecting high confidentiality and availability impact.

Affected products

  • Oracle Siebel CRM 17.0–26.7

Timeline

  • 2026-09-15: disclosed

References

Related threats