Executive brief
Oracle Siebel CRM is a customer relationship management system used by enterprises to manage customer interactions and business data. A vulnerability in the Workspaces component allows unauthenticated attackers on the network to gain unauthorized access to critical customer data and cause service disruptions without requiring any credentials or user interaction.
Technical details
An easily exploitable vulnerability in the Siebel CRM Development Workspaces component allows unauthenticated remote attackers with network access via HTTP to compromise the system. The vulnerability requires no authentication, user interaction, or complex configuration to exploit. Successful exploitation results in unauthorized access to critical data, complete access to all Siebel CRM Development accessible data, and the ability to cause partial denial of service. The affected versions range from 17.0 to 26.7.
Affected products
- Oracle Siebel CRM 17.0-26.7
Timeline
- 2026-09-15: disclosed