---
id: CVE-2026-83145
title: >-
  Vulnerability in the Siebel Apps - Customer Order Management product of Oracle
  Siebel CRM (component: Order Management)
summary: >-
  Vulnerability in the Siebel Apps - Customer Order Management product of Oracle
  Siebel CRM (component: Order Management).  Supported versions that are
  affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged
  attacker…
severity: high
cvss: 8.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'
cwe:
  - CWE-284
vendor: Oracle Corporation
product: Siebel Apps - Customer Order Management
affected:
  - siebel_apps_-_customer_order_management >= 17.0 <= 26.7
published: '2026-09-15'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:16:47.657'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-83145'
references:
  - url: 'https://www.oracle.com/security-alerts/cspusep2026.html'
    label: secalert_us@oracle.com
tags:
  - nvd
  - cve.org
epss: 0.00315
epssPercentile: 0.24625
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-18T18:16:54.772242Z'
ingestedAt: '2026-09-15T20:44:02.468Z'
---

## Overview

Vulnerability in the Siebel Apps - Customer Order Management product of Oracle Siebel CRM (component: Order Management).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps - Customer Order Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel Apps - Customer Order Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel Apps - Customer Order Management accessible data as well as  unauthorized access to critical data or complete access to all Siebel Apps - Customer Order Management accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
