CVE-2026-82992: High severity Oracle Siebel CRM Deployment vulnerability
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Installation). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Deployment executes to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Oracle Siebel CRM Deployment installations on supported versions 17.0 through 26.7 are affected. Exploitation requires access to the infrastructure where Siebel CRM Deployment executes.
What level of access does an attacker need?
An attacker needs a low-privileged account and logon access to the affected infrastructure. No user interaction is required, and the attack vector is local.
What could happen if the vulnerability is exploited?
A successful attack can result in takeover of Siebel CRM Deployment, with high impacts to confidentiality, integrity, and availability.