Junglewise Threat Intelligence

CVE-2026-83228: Oracle Siebel CRM Deployment denial of service in Server Infrastructure

CVE-2026-83228 · Severity: high · CVSS 7.5 · Published 2026-09-15

Executive brief

Siebel CRM Deployment is Oracle's customer relationship management system used to manage business interactions. An unauthenticated attacker with network access can remotely crash or hang the Siebel server, causing complete service unavailability and disrupting customer-facing operations and internal sales/service teams.

Technical details

This is a denial-of-service vulnerability in the Server Infrastructure component of Siebel CRM Deployment. The vulnerability is easily exploitable and requires only network access via TCP with no authentication or user interaction. An unauthenticated attacker can send malformed or crafted network traffic to cause the affected service to hang or crash repeatedly, resulting in complete denial of service. The vulnerability affects versions 17.0 through 26.7, and patches are expected from Oracle.

Affected products

  • Oracle Siebel CRM Deployment 17.0 through 26.7

Timeline

  • 2026-09-15: disclosed

References

Related threats