Junglewise Threat Intelligence

CVE-2026-83229: Oracle Siebel CRM privilege escalation in Management Console

CVE-2026-83229 · Severity: critical · CVSS 9.1 · Published 2026-09-15

Executive brief

Oracle Siebel CRM is a widely-deployed customer relationship management platform used by enterprises to manage customer interactions and business processes. A privilege escalation vulnerability in the Siebel Management Console allows a high-privileged attacker with network access to take complete control of the system and potentially impact other connected products. Successful exploitation could result in unauthorized access to sensitive customer data, operational disruption, and system compromise.

Technical details

This is a privilege escalation vulnerability in the Siebel Management Console component of Oracle Siebel CRM that can be exploited by a high-privileged attacker over the network via HTTP. The vulnerability has a low complexity attack vector (AC:L) and requires no user interaction, making it relatively straightforward to exploit once network access is obtained. Successful exploitation allows an attacker to achieve complete compromise of the Siebel CRM Deployment system with impacts on confidentiality, integrity, and availability. The vulnerability affects versions 17.0 through 26.7, and patches should be obtained from Oracle.

Affected products

  • Oracle Siebel CRM 17.0-26.7

Timeline

  • 2026-09-15: disclosed

References

Related threats