Description
Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Workflow). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Development. Successful attacks of this vulnerability can result in takeover of Siebel CRM Development. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the Workflow component of Oracle Siebel CRM Development, and it permits a low-privileged attacker to gain full control over the application when accessing the system through HTTP. The flaw effectively allows an adversary to execute arbitrary code and thereby compromise confidentiality, integrity and availability of the system. Based on the description, it is inferred that the weakness can be categorized under improper access control and authentication bypass, enabling a remote attacker to perform actions normally restricted to higher-privilege users.

Affected Systems

Oracle Corporation offers the Siebel CRM Development product, versions 17.0 through 26.7, which are affected. The issue specifically targets the Workflow component and affects deployments HTTP interfaces.

Risk and Exploitability

The CVSS 3.1 base score of 8.8 rates this as a high-severity vulnerability, and the EPSS score is below 1%, indicating a relatively. Although the vulnerability is not listed in the CISA KEV catalog, it is easily exploitable via a network connection from outside the protected environment. An attacker with limited privileges can achieve full takeover if the product is reachable over HTTP, making the risk of compromise significant regardless of the low EPSS.

Generated by OpenCVE AI on September 17, 2026 at 01:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor's official patch for Siebel CRM Development that addresses the Workflow component vulnerability.
  • Restrict HTTP access to the Siebel CRM Development deployment to a trusted internal network or VPN, ensuring that only authorized users can reach the exposed endpoints.
  • If immediate patching is not possible, enforce a network-level firewall rule that blocks all external HTTP traffic to the affected ports until the patch is deployed.

Generated by OpenCVE AI on September 17, 2026 at 01:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege Remote Code Execution via HTTP in Oracle Siebel CRM Workflow
Weaknesses CWE-284
CWE-285

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Workflow). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Development. Successful attacks of this vulnerability can result in takeover of Siebel CRM Development. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle siebel Crm Development
CPEs cpe:2.3:a:oracle:siebel_crm_development:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Development
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Siebel Crm Development
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T20:04:21.967Z

Reserved: 2026-08-31T15:40:57.346Z

Link: CVE-2026-83209

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:32.537

Modified: 2026-09-16T19:36:43.087

Link: CVE-2026-83209

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T02:00:10Z

Weaknesses