Junglewise Threat Intelligence

CVE-2026-83219: Oracle Siebel CRM privilege escalation in Server Infrastructure

CVE-2026-83219 · Severity: high · CVSS 7.1 · Published 2026-09-15

Executive brief

Oracle Siebel CRM is an enterprise customer relationship management system used to manage customer interactions and business data. A vulnerability in the Server Infrastructure component allows a low-privileged user with local access to the system to gain unauthorized read and write access to critical CRM data, including customer records and sensitive business information.

Technical details

This is a local privilege escalation vulnerability in the Server Infrastructure component of Oracle Siebel CRM Deployment affecting versions 17.0 through 26.7. The vulnerability requires local logon access and low user privileges but no user interaction to exploit. A successful attack allows an attacker to read and modify all CRM-accessible data without proper authorization, compromising both confidentiality and integrity of the system. Patches are expected to be available from Oracle; users should check the October 2026 security patch list for remediation.

Affected products

  • Oracle Siebel CRM 17.0-26.7

Timeline

  • 2026-09-15: disclosed

References

Related threats