Description
Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTPS to compromise Siebel CRM End User. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel CRM End User, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM End User accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM End User accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N).
Published: 2026-08-18
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Open UI component of the Oracle Siebel CRM End User product and allows a low‑privileged attacker with network access over HTTPS to compromise the application. Successful exploitation requires the attacker to have human interaction from a user other than the attacker, but it can result in unauthorized creation, deletion or modification of critical data and full unauthorized access to all data accessible through Siebel CRM End User. The impact affects confidentiality and integrity, and, due to application scope changes, could also influence other products that interact with the compromised system.

Affected Systems

Prerequisite for exploitation are the Oracle Siebel CRM End User versions 17.0 through 26.6, as those are the specifically supported versions identified as affected. No additional version data is provided.

Risk and Exploitability

The CVSS 3.1 base score of 7.7 signals a high‑impact vulnerability, with the scaled vector reflecting network access, high attack complexity, low privilege, required user interaction, and a change of scope that allows the attacker to affect data beyond the initial target. The EPSS score is 0.00231 and indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, indicating that no publicly confirmed exploitation has been documented to date. The likely attack vector is a remote HTTPS connection, where an attacker with limited permissions can send crafted requests once a user interacts with the vulnerable interface.

Generated by OpenCVE AI on August 21, 2026 at 05:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle Siebel CRM End User to a version that contains the vendor’s security fix for the Open UI component.
  • Restrict access to the Open UI interface to authenticated, privileged users only, enforce HTTPS and multi‑factor authentication to reduce the risk of low‑privileged exploitation.
  • Implement continuous monitoring of data modification actions and audit logs for anomalous behavior that may indicate exploitation attempts.

Generated by OpenCVE AI on August 21, 2026 at 05:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Oracle siebel Crm
CPEs cpe:2.3:a:oracle:siebel_crm:*:*:*:*:*:*:*:*
Vendors & Products Oracle siebel Crm

Fri, 21 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Access via Open UI in Oracle Siebel CRM End User

Wed, 19 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Title Open UI Vulnerability Enabling Unauthorized Data Access in Oracle Siebel CRM End User
Weaknesses CWE-200
CWE-284

Wed, 19 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Title Open UI Vulnerability Enabling Unauthorized Data Access in Oracle Siebel CRM End User
Weaknesses CWE-200
CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTPS to compromise Siebel CRM End User. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel CRM End User, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM End User accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM End User accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle siebel Crm End User
CPEs cpe:2.3:a:oracle:siebel_crm_end_user:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm End User
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Siebel Crm Siebel Crm End User
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T03:56:30.974Z

Reserved: 2026-08-04T22:06:34.602Z

Link: CVE-2026-70857

cve-icon Vulnrichment

Updated: 2026-08-19T18:16:55.870Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:41.867

Modified: 2026-08-21T15:12:08.597

Link: CVE-2026-70857

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T06:00:11Z

Weaknesses