CVE-2026-83181
moderateUnauthenticated Data Access Flaw in Oracle Siebel CRM Workspaces (v17.0–26.7)
Oracle Siebel CRM contains an easily exploitable vulnerability in the Workspaces component of the Siebel CRM Development product, affecting supported versions 17.0 through 26.7. An unauthenticated remote attacker with network access via HTTP can trigger the flaw with low attack complexity and no user interaction. Successful exploitation allows unauthorized read access to critical data — up to complete access to all data accessible to Siebel CRM Development — and the ability to cause a partial denial of service, with no impact on data integrity (CVSS 3.1 base score 8.2). Organizations running affected Siebel CRM versions, especially those with HTTP-reachable Workspaces endpoints, are at risk. The flaw is not in CISA's KEV catalog and no public proof-of-concept exists, so no active exploitation has been confirmed.
What to do: Apply the Oracle Critical Patch Update that remediates this CVE to all Siebel CRM installations running versions 17.0–26.7, prioritizing systems whose Workspaces endpoints are reachable over HTTP. Restrict network access to Siebel application servers (segmentation, VPN, or allow-listing) so unauthenticated HTTP requests cannot reach Workspaces. Review HTTP access logs for anomalous unauthenticated requests to Workspaces paths and investigate any unexplained data access or partial service outages.
| Oracle Siebel CRM (Development product, Workspaces component) | 17.0-26.7 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Workspaces). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Development. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Development accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM Development. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.