ZeroHour

CVE-2026-83181

moderate

Unauthenticated Data Access Flaw in Oracle Siebel CRM Workspaces (v17.0–26.7)

CVSS 3.1
8.2 high
EPSS
Published
()
Modified
AI analysis

Oracle Siebel CRM contains an easily exploitable vulnerability in the Workspaces component of the Siebel CRM Development product, affecting supported versions 17.0 through 26.7. An unauthenticated remote attacker with network access via HTTP can trigger the flaw with low attack complexity and no user interaction. Successful exploitation allows unauthorized read access to critical data — up to complete access to all data accessible to Siebel CRM Development — and the ability to cause a partial denial of service, with no impact on data integrity (CVSS 3.1 base score 8.2). Organizations running affected Siebel CRM versions, especially those with HTTP-reachable Workspaces endpoints, are at risk. The flaw is not in CISA's KEV catalog and no public proof-of-concept exists, so no active exploitation has been confirmed.

What to do: Apply the Oracle Critical Patch Update that remediates this CVE to all Siebel CRM installations running versions 17.0–26.7, prioritizing systems whose Workspaces endpoints are reachable over HTTP. Restrict network access to Siebel application servers (segmentation, VPN, or allow-listing) so unauthenticated HTTP requests cannot reach Workspaces. Review HTTP access logs for anomalous unauthenticated requests to Workspaces paths and investigate any unexplained data access or partial service outages.

Affected
Oracle Siebel CRM (Development product, Workspaces component)17.0-26.7
Estimated exposure
moderate≈ a few thousand enterprise deployments, with likely only hundreds to low thousands of internet-exposed Siebel servers — Siebel CRM is legacy enterprise software with a base of roughly a few thousand large-organization customers, and public internet scans typically show only hundreds to a few thousand exposed Siebel application servers because most…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Workspaces). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Development. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Development accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM Development. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L

In the news

No ingested article mentions this CVE yet.