{
  "cve": "CVE-2026-83195",
  "enrichment": {
    "affected": [
      {
        "configurations": [
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "generic",
              "value": "[17.0,26.7]"
            }
          }
        ],
        "enrichment": {
          "confidence": 95.0,
          "confidence_source": "inferred",
          "scores": [
            {
              "score": 95.0,
              "source": "inferred"
            },
            {
              "score": 100.0,
              "source": "matching"
            }
          ]
        },
        "original": {
          "product": "Siebel CRM Deployment",
          "source": "cna",
          "vendor": "Oracle Corporation"
        },
        "product": "siebel_crm_deployment",
        "vendor": "oracle"
      }
    ],
    "created": "2026-09-16T03:00:13.453914+00:00",
    "title": "High‑Severity Remote Privilege Escalation Vulnerability in Oracle Siebel CRM Deployment",
    "updated": "2026-09-20T09:15:17.434914+00:00",
    "vendors": [
      "oracle",
      "oracle$PRODUCT$siebel_crm_deployment"
    ]
  },
  "epss": {
    "score": 0.00462
  },
  "mitre": {
    "cpes": [
      "cpe:2.3:a:oracle:siebel_crm_deployment:*:*:*:*:*:*:*:*"
    ],
    "created": "2026-09-15T20:04:17.514000+00:00",
    "description": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows high privileged attacker with network access via TCP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 7.2,
        "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
      },
      "cvssV4_0": {}
    },
    "mitre_repo_path": "cves/2026/83xxx/CVE-2026-83195.json",
    "references": [
      "https://www.oracle.com/security-alerts/cspusep2026.html"
    ],
    "title": null,
    "updated": "2026-09-17T13:10:41.918000+00:00",
    "vendors": [
      "oracle",
      "oracle$PRODUCT$siebel_crm_deployment"
    ],
    "weaknesses": []
  },
  "nvd": {
    "cpes": [],
    "created": "2026-09-15T20:18:30.940000+00:00",
    "description": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows high privileged attacker with network access via TCP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 7.2,
        "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
      },
      "cvssV4_0": {}
    },
    "nvd_repo_path": "2026/CVE-2026-83195.json",
    "references": [
      "https://www.oracle.com/security-alerts/cspusep2026.html"
    ],
    "title": null,
    "updated": "2026-09-17T14:17:36.160000+00:00",
    "vendors": [],
    "weaknesses": [
      "CWE-269"
    ]
  },
  "opencve": {
    "changes": [
      {
        "created": "2026-09-15T20:15:00+00:00",
        "data": [
          {
            "details": {
              "new": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows high privileged attacker with network access via TCP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
              "old": null
            },
            "type": "description"
          },
          {
            "details": [
              "oracle",
              "oracle$PRODUCT$siebel_crm_deployment"
            ],
            "type": "first_time"
          },
          {
            "details": {
              "added": [
                "cpe:2.3:a:oracle:siebel_crm_deployment:*:*:*:*:*:*:*:*"
              ],
              "removed": []
            },
            "type": "cpes"
          },
          {
            "details": {
              "added": [
                "oracle",
                "oracle$PRODUCT$siebel_crm_deployment"
              ],
              "removed": []
            },
            "type": "vendors"
          },
          {
            "details": {
              "added": [
                "https://www.oracle.com/security-alerts/cspusep2026.html"
              ],
              "removed": []
            },
            "type": "references"
          },
          {
            "details": {
              "added": {
                "cvssV3_1": {
                  "score": 7.2,
                  "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "5d3f9bd2-8400-43e5-bcdf-e15bdbcbadb1"
      },
      {
        "created": "2026-09-16T22:30:00+00:00",
        "data": [
          {
            "details": {
              "new": "Siebel CRM Deployment Privilege Escalation via TCP Network Access",
              "old": null
            },
            "type": "title"
          },
          {
            "details": {
              "added": [
                "CWE-269",
                "CWE-284"
              ],
              "removed": []
            },
            "type": "weaknesses"
          }
        ],
        "id": "58b091d5-5dc6-4e4d-beca-420aa89f6e0f"
      },
      {
        "created": "2026-09-17T14:30:00+00:00",
        "data": [
          {
            "details": {
              "added": {
                "ssvc": {
                  "options": {
                    "Automatable": "no",
                    "Exploitation": "none",
                    "Technical Impact": "total"
                  },
                  "version": "2.0.3"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "4394d271-983f-4ed6-9bf9-2209c9edcfaf"
      },
      {
        "created": "2026-09-18T21:30:00+00:00",
        "data": [
          {
            "details": {
              "new": null,
              "old": "Siebel CRM Deployment Privilege Escalation via TCP Network Access"
            },
            "type": "title"
          },
          {
            "details": {
              "added": [],
              "removed": [
                "CWE-284"
              ]
            },
            "type": "weaknesses"
          }
        ],
        "id": "c82d0496-aaf0-4725-9725-b9b24b44f213"
      },
      {
        "created": "2026-09-20T09:30:00+00:00",
        "data": [
          {
            "details": {
              "new": "High‑Severity Remote Privilege Escalation Vulnerability in Oracle Siebel CRM Deployment",
              "old": null
            },
            "type": "title"
          }
        ],
        "id": "e305cec6-5a61-46e9-baf2-1793a0afc5ea"
      }
    ],
    "cpes": {
      "data": [
        "cpe:2.3:a:oracle:siebel_crm_deployment:*:*:*:*:*:*:*:*"
      ],
      "providers": [
        "mitre"
      ]
    },
    "created": {
      "data": "2026-09-15T20:04:17.514000+00:00",
      "provider": "mitre"
    },
    "description": {
      "data": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows high privileged attacker with network access via TCP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "provider": "mitre"
    },
    "metrics": {
      "cvssV2_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_1": {
        "data": {
          "score": 7.2,
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        "provider": "mitre"
      },
      "cvssV4_0": {
        "data": {},
        "provider": null
      },
      "epss": {
        "data": {
          "score": 0.00462
        },
        "provider": "first"
      },
      "kev": {
        "data": {},
        "provider": null
      },
      "ssvc": {
        "data": {
          "options": {
            "Automatable": "no",
            "Exploitation": "none",
            "Technical Impact": "total"
          },
          "version": "2.0.3"
        },
        "provider": "vulnrichment"
      },
      "threat_severity": {
        "data": null,
        "provider": null
      }
    },
    "references": {
      "data": [
        "https://www.oracle.com/security-alerts/cspusep2026.html"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    },
    "title": {
      "data": "High‑Severity Remote Privilege Escalation Vulnerability in Oracle Siebel CRM Deployment",
      "provider": "enrichment"
    },
    "updated": {
      "data": "2026-09-20T09:15:17.434914+00:00",
      "provider": "enrichment"
    },
    "vendors": {
      "data": [
        "oracle",
        "oracle$PRODUCT$siebel_crm_deployment"
      ],
      "providers": [
        "mitre",
        "enrichment"
      ]
    },
    "weaknesses": {
      "data": [
        "CWE-269"
      ],
      "providers": [
        "nvd",
        "vulnrichment"
      ]
    }
  },
  "vulnrichment": {
    "cpes": [],
    "created": "2026-09-15T20:04:17.514000+00:00",
    "description": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows high privileged attacker with network access via TCP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {},
      "cvssV4_0": {},
      "kev": {},
      "ssvc": {
        "options": {
          "Automatable": "no",
          "Exploitation": "none",
          "Technical Impact": "total"
        },
        "version": "2.0.3"
      }
    },
    "references": [],
    "title": null,
    "updated": "2026-09-17T13:01:42.755000+00:00",
    "vendors": [],
    "vulnrichment_repo_path": "2026/83xxx/CVE-2026-83195.json",
    "weaknesses": [
      "CWE-269"
    ]
  }
}