OracleCVE-2026-83182
Siebel CRM Development: takeover via Configuration Tools
High7.5CVE-2026-83182 · Published Sep 15, 2026 · updated Sep 17, 2026
Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Configuration Tools). Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability allows low privileged attacker with network access via SQL to compromise Siebel CRM Development. Successful attacks of this vulnerability can result in takeover of Siebel CRM Development. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Siebel CRM Development Product | >= 17.0, <= 26.7 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-284
More Oracle advisories
All Oracle| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 15 | Oracle GraalVM for JDK: takeover via Compiler | High8.1 | No fix yet |
| Sep 15 | Oracle GraalVM for JDK: data tampering via Compiler | High7.0 | No fix yet |
| Sep 15 | Oracle GraalVM for JDK: takeover via Compiler | High8.1 | No fix yet |
| Sep 15 | Oracle VM VirtualBox: flaw in Core | Low3.2 | No fix yet |
| Sep 15 | Oracle VM VirtualBox: denial of service via Core | Medium6.0 | No fix yet |
| Sep 15 | Oracle GraalVM: takeover via Compiler | High8.1 | No fix yet |