Description
Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Workflow). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Development. Successful attacks of this vulnerability can result in takeover of Siebel CRM Development. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The flaw lies in the Workflow component of Oracle Siebel CRM Development, enabling a low-privileged attacker with network access over HTTP to execute arbitrary code. Because the vulnerability is classified under improper access control (CWE‑284), the attacker can bypass normal authentication checks and gain full control, thereby compromising confidentiality, integrity, and availability of the application.

Affected Systems

Oracle Corporation’s Siebel CRM Development product, specifically versions 17.0 through 26.7, is impacted. The vulnerability targets the Workflow component and is exploitable via the HTTP interface exposed by these deployments.

Risk and Exploitability

The CVSS 3.1 base score of 8.8 reflects high severity, while the EPSS score is less than 1 percent, indicating a low exploitation probability at present. Nevertheless, the vulnerability is easily exploitable from a remote network connection, and it is not listed in the CISA KEV catalog. A low‑privileged attacker who can reach the HTTP endpoints can take over the entire application, posing significant risk even with the low EPSS.

Generated by OpenCVE AI on September 20, 2026 at 08:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official Oracle patch for Siebel CRM Development that addresses the Workflow component flaw.
  • Restrict HTTP access to the Siebel CRM Development deployment by limiting connectivity to a trusted internal network or VPN, ensuring that only authorized users can reach the exposed endpoints.
  • If patching cannot be performed immediately, enforce a network‑level firewall rule that blocks all external HTTP traffic on the affected ports until the fix is applied.

Generated by OpenCVE AI on September 20, 2026 at 08:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Workflow Access Control Bypass in Oracle Siebel CRM Development

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege Remote Code Execution via HTTP in Oracle Siebel CRM Workflow
Weaknesses CWE-285

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege Remote Code Execution via HTTP in Oracle Siebel CRM Workflow
Weaknesses CWE-284
CWE-285

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Workflow). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Development. Successful attacks of this vulnerability can result in takeover of Siebel CRM Development. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle siebel Crm Development
CPEs cpe:2.3:a:oracle:siebel_crm_development:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Development
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Siebel Crm Development
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:14:05.943Z

Reserved: 2026-08-31T15:40:57.346Z

Link: CVE-2026-83209

cve-icon Vulnrichment

Updated: 2026-09-17T14:58:19.043Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:32.537

Modified: 2026-09-17T16:18:09.870

Link: CVE-2026-83209

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T09:00:13Z

Weaknesses