CVE-2026-83197
Deferred Deferred - Pending Action

Unauthenticated Remote Code Execution in Siebel Apps - Financial Services

Vulnerability report for CVE-2026-83197, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-21

Assigner: Oracle

Description

Vulnerability in the Siebel Apps - Financial Services product of Oracle Siebel CRM (component: Financial Accounts). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Financial Services. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel Apps - Financial Services accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel Apps - Financial Services. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-21
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
oracle siebel_crm From 17.0 (inc) to 26.7 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a vulnerability in Oracle Siebel CRM's Financial Services product affecting versions 17.0 to 26.7. It allows an unauthenticated attacker with network access via HTTP to exploit it. Successful exploitation can lead to unauthorized access to critical data or complete access to all accessible data in Siebel Apps - Financial Services. It can also cause the system to hang or crash repeatedly, resulting in a denial of service (DOS).

Detection Guidance

This vulnerability affects Oracle Siebel CRM's Financial Services component versions 17.0-26.7. Detection requires checking for unpatched versions of this software. Inspect installed Siebel CRM versions via system logs or application directories. Monitor network traffic for unusual HTTP requests targeting Siebel services. Check Oracle's security advisories for patch availability.

Impact Analysis

If you use Oracle Siebel CRM's Financial Services product, an attacker could gain unauthorized access to sensitive financial or customer data. This could lead to data breaches, financial loss, or disruption of services due to system crashes or hangs.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR and HIPAA compliance requirements. Organizations may face legal penalties, fines, or reputational damage if such breaches occur due to this vulnerability.

Mitigation Strategies

Apply the latest Oracle Siebel CRM patches for versions 17.0-26.7 to address the vulnerability in the Financial Accounts component. Ensure network access controls restrict HTTP traffic to trusted sources only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-83197. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart