Junglewise Threat Intelligence

CVE-2026-83226: Oracle Siebel CRM Deployment remote code execution in Server Infrastructure

CVE-2026-83226 · Severity: high · CVSS 7.5 · Published 2026-09-15

Executive brief

Siebel CRM Deployment is a customer relationship management system used to manage enterprise customer interactions and business processes. A vulnerability in the Server Infrastructure component allows a low-privileged attacker with network access to remotely execute code and gain complete control of the Siebel CRM system, potentially compromising all customer data and business operations that depend on it.

Technical details

This is a remote code execution (RCE) vulnerability in Oracle Siebel CRM Deployment versions 17.0 through 26.7, affecting the Server Infrastructure component. The vulnerability is accessible over the network via HTTP and requires low privilege credentials to exploit, but has high complexity, suggesting specific preconditions or bypass techniques are required. A successful exploit grants an attacker complete control over the CRM Deployment system with full confidentiality, integrity, and availability impact. The CVSS 3.1 score of 7.5 reflects the high impact combined with the elevated complexity and authentication requirement.

Affected products

  • Oracle Siebel CRM Deployment 17.0-26.7

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: other: Oracle security alert published

References

Related threats