ZeroHour

CVE-2026-83209

moderate

Low-Privilege Takeover Flaw in Oracle Siebel CRM Workflow Component

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83209 is a high-severity (CVSS 8.8) vulnerability in the Workflow component of Oracle Siebel CRM's Development product, affecting all supported versions from 17.0 through 26.7. It is easily exploitable by a low-privileged (authenticated) attacker who has network access to the Siebel CRM Development environment via HTTP, requiring no user interaction. A successful attack allows the attacker to fully compromise the Siebel CRM Development environment, with high impact on confidentiality, integrity, and availability — effectively a complete takeover. Any organization running a supported Siebel CRM release in that version range with a reachable Development environment is affected. There is no known public proof-of-concept, the flaw is not on the CISA KEV list, and no in-the-wild exploitation has been reported to date.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83209 to any Siebel CRM installation running versions 17.0 through 26.7. Ensure Development environments are not exposed to the internet and are reachable only from trusted internal networks or over VPN. Review Workflow configurations and audit logs for unauthorized changes or suspicious activity by low-privileged accounts, and enforce least-privilege access on Siebel application accounts.

Affected
Oracle Siebel CRM (Siebel CRM Development, component: Workflow)17.0 - 26.7
Estimated exposure
moderatelow thousands of Siebel deployments potentially affected (likely a few thousand internet-reachable Siebel hosts, with exposed Development environments a… — Siebel CRM is enterprise software deployed by thousands of large organizations, typically on-premises, and public internet scan data historically shows only low thousands of exposed Siebel servers — Development environments, usually…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Workflow). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Development. Successful attacks of this vulnerability can result in takeover of Siebel CRM Development. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.