CVE-2026-83229
Received Received - Intake

Remote Code Execution in Siebel CRM Deployment

Vulnerability report for CVE-2026-83229, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: Oracle

Description

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Siebel Management Console). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. While the vulnerability is in Siebel CRM Deployment, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-10-06
AI Q&A
2026-09-15
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
oracle siebel_crm_deployment From 17.0 (inc) to 26.7 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a vulnerability in Oracle Siebel CRM Deployment, specifically in the Siebel Management Console component. It affects versions 17.0 to 26.7. An attacker with high privileges and network access via HTTP can exploit it to take over the Siebel CRM Deployment system. The vulnerability has a CVSS score of 9.1, indicating high impact on confidentiality, integrity, and availability.

Detection Guidance

Detection of CVE-2026-83229 requires checking for vulnerable versions of Oracle Siebel CRM Deployment (17.0-26.7) via system inventory or patch management tools. Inspect HTTP traffic for unusual requests targeting the Siebel Management Console. Monitor for unauthorized administrative access or takeover attempts in logs.

Impact Analysis

If exploited, this vulnerability allows an attacker to fully compromise the Siebel CRM Deployment system. This could lead to unauthorized access, data breaches, system manipulation, or complete takeover of the affected product, potentially impacting other connected systems.

Compliance Impact

This vulnerability allows high privileged attackers to compromise Siebel CRM Deployment, potentially leading to unauthorized access, data breaches, or system takeover. Such impacts could violate GDPR (data protection), HIPAA (health data security), or other regulations by exposing sensitive information or disrupting critical operations.

Mitigation Strategies

Apply the latest security patches from Oracle for Siebel CRM Deployment versions 17.0-26.7. Restrict network access to the Siebel Management Console via HTTP. Monitor for unusual activity and unauthorized access attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-83229. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart