Description
Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM End User. Successful attacks of this vulnerability can result in takeover of Siebel CRM End User. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Compromise
Action: Immediate Patch
AI Analysis

Impact

The vulnerability exists in the Open UI component of Oracle Siebel CRM End User, permitting an unauthenticated attacker with network access via HTTP to compromise the entire system. Successful exploitation results in a full takeover, leading to complete loss of confidentiality, integrity, and availability. The root weakness is inadequate enforcement of authentication and access controls, represented by CWE-269.

Affected Systems

Oracle Siebel CRM End User, versions 17.0 through 26.7, is affected. Any deployment still employing the legacy Open UI interface is vulnerable.

Risk and Exploitability

The CVSS v3.1 base score of 8.1 signals a high severity flaw, while the EPSS score of less than 1% indicates a low probability of current exploitation. It is not listed in the CISA KEV catalog. Attackers need only network connectivity to the exposed HTTP service and no authentication to trigger the exploit, though the high access complexity suggests that technical barriers exist. Once the flaw is exploited, the impact is total takeover of the Siebel CRM End User instance.

Generated by OpenCVE AI on September 20, 2026 at 09:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor patch or upgrade to any version beyond 26.7 as detailed in the Oracle security alert at https://www.oracle.com/security-alerts/cspusep2026.html.
  • If an official patch is not yet available, restrict inbound HTTP traffic to the Siebel CRM End User server by implementing firewall rules or network segmentation that allow only trusted hosts.
  • Disable or remove any default or guest accounts exposed through the Open UI component and enforce strict authentication for all users.
  • Monitor application logs and network traffic for suspicious HTTP requests and configure alerts for potential exploitation attempts.

Generated by OpenCVE AI on September 20, 2026 at 09:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit Enables Full Takeover of Siebel CRM End User

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Compromise via Open UI in Siebel CRM End User
Weaknesses CWE-284
CWE-287

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Compromise via Open UI in Siebel CRM End User
Weaknesses CWE-284
CWE-287

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM End User. Successful attacks of this vulnerability can result in takeover of Siebel CRM End User. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle siebel Crm End User
CPEs cpe:2.3:a:oracle:siebel_crm_end_user:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm End User
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Siebel Crm End User
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:10:42.358Z

Reserved: 2026-08-31T15:40:57.345Z

Link: CVE-2026-83192

cve-icon Vulnrichment

Updated: 2026-09-17T13:01:49.308Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:30.610

Modified: 2026-09-17T14:17:35.757

Link: CVE-2026-83192

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T09:15:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management