A CVSS 9.1 vulnerability in Oracle Siebel CRM's Financial Services application lets unauthenticated attackers reach critical data and knock the product offline over plain HTTP.
What Is It
CVE-2026-83197 is a critical vulnerability in the Siebel Apps – Financial Services product of Oracle Siebel CRM, specifically the Financial Accounts component. Oracle describes it as easily exploitable: an unauthenticated attacker with network access via HTTP can compromise the application with no user interaction and no privileges required.
The CVSS 3.1 base score is 9.1 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H. Exploitability scores at the maximum 3.9. Impact is split between confidentiality and availability; integrity is untouched.
Why It Matters
Two outcomes are on the table. First, unauthorized access to critical data, or complete access to all data reachable by Siebel Apps – Financial Services. Second, an unauthorized ability to cause a hang or a frequently repeatable crash; a complete denial of service against the application.
The combination is what makes this one urgent. There is no authentication barrier, no social engineering step, and the attack complexity is rated LOW. A bank or insurer running Siebel for customer financial account workflows would be exposing both the records and the availability of that system to anyone who can reach it over HTTP.
The record was published 2026-09-15 with a status of "Received," meaning NVD analysis is still pending. The supplied source material contains no CISA KEV entry for this CVE, so there is no confirmed active exploitation at this time.
What's Vulnerable
- Vendor: Oracle Corporation
- Product: Siebel Apps – Financial Services (Oracle Siebel CRM)
- Component: Financial Accounts
- Affected versions: 17.0 through 26.7 inclusive
That is a nine-year version band. Organizations that have deferred Siebel upgrades are almost certainly in scope, and any deployment still running a release inside that band should be treated as affected until proven otherwise.
Patch Status
Patch availability for this CVE could not be confirmed from the supplied source material. Oracle ships fixes for Siebel CRM through its quarterly Critical Patch Update cycle, which lands in January, April, July, and October; there is no September CPU, so a fix for a 2026-09-15 record would be expected in the October 2026 CPU at the earliest, unless Oracle issues an out-of-cycle Security Alert.
Administrators should check Oracle's Critical Patch Update and Security Alerts index directly for an advisory naming CVE-2026-83197, and apply the corresponding fix for their Siebel release once it is published. In the interim, restrict network reachability to Siebel Apps – Financial Services endpoints, since the flaw requires no credentials. No specific CISA-mandated remediation deadline applies, as the CVE is not present in the supplied KEV catalog data.
Sources
- NVD, CVE-2026-83197: https://nvd.nist.gov/vuln/detail/CVE-2026-83197
- Oracle; Critical Patch Updates, Security Alerts and Bulletins (quarterly CPU schedule and advisory index): https://www.oracle.com/security-alerts/
- Oracle security alert link as supplied in source material (unverified; this URL does not match Oracle's published advisory naming and may not resolve; use Oracle's Critical Patch Update index to locate the authoritative advisory): https://www.oracle.com/security-alerts/cspusep2026.html