Junglewise Threat Intelligence

CVE-2026-83220: Oracle Siebel CRM Integration unauthorized data access in Event Publish and Subscribe

CVE-2026-83220 · Severity: high · CVSS 8.1 · Published 2026-09-15

Technologies: Oracle Siebel CRM Integration. Vendors: Oracle.

Executive brief

Oracle Siebel CRM Integration is an enterprise customer relationship management platform used to manage critical customer data and business operations. A vulnerability in the Event Publish and Subscribe component allows an attacker with physical access to the network segment to bypass authentication and read, modify, or delete sensitive customer data without authorization.

Technical details

The vulnerability exists in the Event Publish and Subscribe component of Siebel CRM Integration and allows unauthenticated attackers with adjacent network access to compromise the system. The attack vector is adjacent network (physical communication segment), requiring no user interaction or privileges, and the configuration is simple (AC:L). Successful exploitation results in high confidentiality and integrity impact—attackers can read, create, modify, or delete critical data accessible through Siebel CRM Integration. Availability is not impacted (A:N). Affected versions are 23.6 through 26.7; patch or version update status is not specified in the advisory.

Affected products

  • Oracle Siebel CRM Integration 23.6 to 26.7

Timeline

  • 2026-09-15: disclosed: CVE-2026-83220 published
  • 2026-09-15: other: No evidence of active exploitation in the wild as of publication date

References

Related threats