Executive brief
Oracle Siebel CRM Development is a customer relationship management platform used by enterprises to manage business interactions and data. A vulnerability in the Workflow component allows a low-privileged network attacker to gain full control of the CRM system, potentially exposing sensitive customer and business data, disrupting operations, and compromising system integrity.
Technical details
This is an easily exploitable vulnerability in the Workflow component of Oracle Siebel CRM Development that requires low-level privileges and network access via HTTP. The vulnerability allows an authenticated attacker with low privileges to achieve complete compromise of the CRM system, resulting in high-impact confidentiality, integrity, and availability violations. Affected versions include 17.0 through 26.7. Patch status and detailed remediation guidance should be obtained from Oracle security advisories.
Affected products
- Oracle Siebel CRM Development 17.0-26.7
Timeline
- 2026-09-15: disclosed