Junglewise Threat Intelligence

CVE-2026-83230: Oracle Siebel CRM unauthorized data access in Management Console

CVE-2026-83230 · Severity: high · CVSS 7.1 · Published 2026-09-15

Executive brief

Oracle Siebel CRM is a customer relationship management platform used to manage business interactions and customer data. A vulnerability in the Siebel Management Console allows authenticated users with low-level network access to read sensitive customer data and modify or delete records without proper authorization. This could lead to exposure of confidential business information and integrity violations of critical CRM data.

Technical details

An authorization or access control vulnerability exists in the Siebel Management Console component of Oracle Siebel CRM. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP, requiring only valid credentials. Successful exploitation results in unauthorized read access to sensitive CRM data (high confidentiality impact) and limited unauthorized update/insert/delete capabilities (low integrity impact). The vulnerability affects versions 17.0 through 26.7; patch availability and mitigation steps should be verified through Oracle's security advisory.

Affected products

  • Oracle Siebel CRM 17.0-26.7

Timeline

  • 2026-09-15: disclosed

References

Related threats