Description
Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM End User. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel CRM End User, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM End User accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM End User accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N).
Published: 2026-09-15
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized creation, modification, or deletion of critical data and potential full access to all Siebel CRM End User data
Action: Immediate Mitigation
AI Analysis

Impact

This vulnerability exists in the Open UI component of the Siebel CRM End User application. A low‑privileged attacker who can reach the system over HTTP can exploit a flaw that requires a second user’s interaction to execute. Successfully exploiting the flaw grants the attacker the ability to create, delete, or alter critical data and, in the worst case, gain complete access to all data that the application exposes. The weakness effectively bypasses existing access controls and, due to a scope change, can affect other connected Siebel products.

Affected Systems

Versions 17.0 through 26.7 of Oracle’s Siebel CRM End User are affected. The vulnerability may also have repercussions for other Siebel components that interact with the End User module, given the documented scope change.

Risk and Exploitability

The CVSS 3.1 Base Score of 7.7 signals high severity, with significant confidentiality and integrity impacts. An EPSS score of less than 1 % indicates that, while exploitation is theoretically feasible, it is presently unlikely to be observed in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers would need network access via HTTP, low privileges, and a second user’s cooperation to trigger the exploit, but once activated the attacker can inflict serious data manipulation or disclosure.

Generated by OpenCVE AI on September 20, 2026 at 09:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Restrict HTTP access to the Siebel CRM End User Open UI interfaces to trusted internal hosts only, blocking any externally reachable entry points.
  • Enforce strict role‑based access control and the principle of least privilege for all users who interact with Open UI, ensuring that only authorized personnel can create, delete, or modify data.
  • Enable comprehensive audit logging for all create, delete, and modify operations through Open UI, and configure real‑time alerts for anomalous activity or repeated unauthorized attempts.
  • When Oracle releases an official security update addressing this issue, immediately apply the patch to all affected versions (17.0‑26.7).

Generated by OpenCVE AI on September 20, 2026 at 09:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Title Siebel CRM End User Open UI Privilege Escalation Leading to Unauthorized Data Manipulation

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Open UI Low‑Privileged Remote Access for Siebel CRM End User
Weaknesses CWE-287
CWE-863

Thu, 17 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Title Open UI Low‑Privileged Remote Access for Siebel CRM End User
Weaknesses CWE-284
CWE-287
CWE-863

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM End User. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel CRM End User, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM End User accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM End User accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle siebel Crm End User
CPEs cpe:2.3:a:oracle:siebel_crm_end_user:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm End User
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Siebel Crm End User
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-18T18:23:51.003Z

Reserved: 2026-08-31T15:40:57.342Z

Link: CVE-2026-83146

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:25.300

Modified: 2026-09-18T19:16:48.190

Link: CVE-2026-83146

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T10:00:09Z

Weaknesses