Impact
The flaw resides in the Document Management component of Oracle Siebel CRM End User, where weak access control allows a low‑privileged attacker with network access via HTTP to execute actions that compromise confidentiality, integrity and availability of the whole application, effectively giving an attacker complete control over the system.
Affected Systems
Oracle Siebel CRM End User versions 17.0 through 26.6 are affected; the vulnerability targets only the Document Management component and does not impact other Oracle product lines.
Risk and Exploitability
The vulnerability carries a CVSS 3.1 base score of 8.8, indicating high severity, and can be exploited remotely over HTTP by a user with low privileges and no user interaction. The EPSS score is less than 1%, suggesting a low but non‑zero likelihood of exploitation in the wild, and the flaw is not listed in CISA KEV. Without an official fix, the risk remains significant, urging immediate implementation of mitigations.
OpenCVE Enrichment