Description
Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Workspaces). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Development. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Development accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM Development. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).
Published: 2026-09-15
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access and Partial Denial of Service via HTTP
Action: Immediate Patch
AI Analysis

Impact

A flaw in Oracle Siebel CRM Development’s Workspaces component allows an unauthenticated attacker gain full access to all data exposed by the application. The vulnerability also enables the The primary impact is a high confidentiality loss with the potential for availability degradation, as reflected in the CVSS 3.1 base score of 8.2.

Affected Systems

Oracle Siebel CRM Development versions 17.0 through 26.7 are affected. The weakness exists in the Workspaces component of the product, which is typically accessible over standard HTTP ports to external users.

Risk and Exploitability

The CVSS score indicates a high severity vulnerability, but the EPSS score is less than 1%, suggesting that exploitation attempts are currently rare. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a simple HTTP request to the vulnerable Workspaces endpoint, once exploited, an attacker can read sensitive data and interrupt services partially, potentially impacting business operations and data confidentiality.

Generated by OpenCVE AI on September 18, 2026 at 20:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Oracle’s latest security patch or upgrade Siebel CRM Development to a version outside the 17.0-26.7 range.
  • If patching is not immediately possible, restrict external HTTP access to the Workspaces component or disable the endpoint entirely.
  • Enable detailed application and web‑server logging to detect suspicious HTTP traffic targeting the vulnerable component.

Generated by OpenCVE AI on September 18, 2026 at 20:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Grants Full Data Access and Partial DoS in Siebel CRM Development

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Grants Full Data Access and Partial DoS in Siebel CRM Development
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Workspaces). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Development. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Development accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM Development. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).
First Time appeared Oracle
Oracle siebel Crm Development
CPEs cpe:2.3:a:oracle:siebel_crm_development:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Development
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L'}


Subscriptions

Oracle Siebel Crm Development
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:15:51.952Z

Reserved: 2026-08-31T15:40:57.345Z

Link: CVE-2026-83181

cve-icon Vulnrichment

Updated: 2026-09-17T14:27:15.838Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:29.247

Modified: 2026-09-17T16:18:07.740

Link: CVE-2026-83181

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:30:16Z

Weaknesses