Junglewise Threat Intelligence

CVE-2026-83218: Oracle Siebel CRM Deployment authentication bypass in Server Infrastructure

CVE-2026-83218 · Severity: high · CVSS 7.4 · Published 2026-09-15

Technologies: Oracle Siebel CRM Deployment. Vendors: Oracle.

Executive brief

Oracle Siebel CRM Deployment is an enterprise customer relationship management platform used to manage customer interactions and business data. An unauthenticated attacker with network access can exploit a flaw in the Server Infrastructure component to bypass authentication and gain unauthorized access to create, modify, or delete critical customer data. This could result in data theft, corruption, or loss of business-critical information.

Technical details

The vulnerability is a network-accessible authentication bypass flaw in the Siebel CRM Deployment Server Infrastructure component. It allows unauthenticated attackers to reach the vulnerable code via HTTP without requiring authentication, user interaction, or valid credentials. Successful exploitation permits unauthorized access to critical data, including the ability to create, delete, and modify records across the Siebel CRM system. The vulnerability affects versions 17.0 through 26.7; patch availability is indicated by the advisory but specific patch versions were not accessible in the provided reference materials.

Affected products

  • Oracle Siebel CRM Deployment 17.0-26.7

Timeline

  • 2026-09-15: disclosed: CVE-2026-83218 published

References

Related threats