Summary
CVE-2026-83074 is a high-severity vulnerability (CVSS 8.6) in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications. It allows an unauthenticated attacker with network access to compromise the affected system, resulting in unauthorized access to critical data. Oracle disclosed the issue as part of its September 2026 Critical Security Patch Update.
Technical details
- Root cause: a flaw in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications that permits unauthorized access to data without valid credentials.
- Trigger conditions: the vulnerability is described by Oracle as "easily exploitable," requiring no authentication and no user interaction.
- Attack vector: network access to the affected component; the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N) indicates a low-complexity network attack with a scope change (Scope: Changed), meaning the vulnerability can impact resources beyond the vulnerable component itself.
- Impact: successful exploitation can result in unauthorized access to critical data or complete access to all data accessible to Siebel CRM Cloud Applications, with no direct impact on integrity or availability.
Affected software
- Oracle Siebel CRM Cloud Applications, component Siebel Cloud Manager, versions 22.3 through 26.7.
Severity
- CVSS v3.1 Base Score: 8.6 (High)
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate: Apply the security patches for Oracle Siebel CRM Cloud Applications (Siebel Cloud Manager component) released in Oracle’s September 2026 Critical Security Patch Update, which addresses CVE-2026-83074 for versions 22.3 through 26.7.
- If patching cannot be applied immediately: restrict network access to the Siebel Cloud Manager component to trusted management networks only, and monitor for unauthorized access attempts until the patch can be deployed.

