CVE-2026-83202
CRITICAL · 9.1Recent publication, no KEV, no PoC, no urgent patching signal yet.
What: Unauthenticated network-accessible remote code/data manipulation in Oracle Siebel CRM Deployment (versions 17.0–26.7), Server Infrastructure component. CVSS 9.1 CRITICAL.
Why it matters: Published 15 Sept 2026, not yet KEV-listed. No public PoC or in-the-wild exploitation confirmed in chatter. Oracle has not issued urgent patches. Social posts are brief, lack technical depth, and mostly echo the CVE description. Early signal but no defender triage activity visible.
Where it's seen: Bluesky posts restating CVSS/affected versions; reference to a third-party CVE aggregator. No vendor advisory, no researcher PoC, no defender questions.
RISK: CRITICAL — Unauthenticated network attack, high impact (confidentiality, integrity), wide version range affected.
Description
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Deployment accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
CVSS 3.1 breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N- Attack vector
- Network
- Complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- None