Junglewise Threat Intelligence

CVE-2026-83224: Oracle Siebel CRM unauthorized access vulnerability in Server Infrastructure

CVE-2026-83224 · Severity: high · CVSS 7.1 · Published 2026-09-15

Executive brief

Oracle Siebel CRM Deployment is a customer relationship management system used by enterprises to manage business operations and customer data. A vulnerability in its Server Infrastructure component allows attackers with low-level network access to view sensitive customer data and disrupt service availability. Successful exploitation could expose critical business data and prevent legitimate users from accessing the CRM system.

Technical details

This vulnerability in Oracle Siebel CRM Deployment (versions 17.0–26.7) is easily exploitable via HTTP by a low-privileged attacker with network access. The attack vector is network-based with low complexity and requires valid credentials (PR:L). Exploitation allows unauthorized access to critical data stored in the CRM and enables partial denial of service. The vulnerability impacts confidentiality (data exposure) and availability (partial service disruption). No patch information is currently available in the advisory, but Oracle has classified this as a high-severity issue with a CVSS score of 7.1.

Affected products

  • Oracle Siebel CRM Deployment 17.0-26.7

Timeline

  • 2026-09-15: disclosed

References

Related threats