Description
Vulnerability in the Siebel Apps - Financial Services product of Oracle Siebel CRM (component: Financial Accounts). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Financial Services. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel Apps - Financial Services accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel Apps - Financial Services. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).
Published: 2026-09-15
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access and Denial of Service
Action: Patch Now
AI Analysis

Impact

This vulnerability is an authentication bypass (CWE‑284) that permits an unauthenticated attacker with network access over HTTP to gain entry to the Oracle Siebel CRM Financial Services Financial Accounts component. Successful exploitation can lead to unauthorized exposure of sensitive data and can also trigger application hangs or repeatable crashes, causing a loss of availability.

Affected Systems

The affected product is Oracle Siebel CRM Financial Services, specifically the Financial Accounts module, in all supported releases from version 17.0 through 26.7 inclusive. These versions are deployed in environments that expose the application over HTTP.

Risk and Exploitability

The CVSS 3.1 base score of 9.1 indicates a high impact on confidentiality and availability, while the EPSS score of less than 1% suggests a low predicted exploitation frequency. Nevertheless, because the flaw is directly reachable over HTTP and requires no authentication, the risk remains significant. The vulnerability is not listed in CISA KEV, but the lack of mitigate controls in the default configuration means that, if discovered, an attacker could readily compromise data and disrupt services.

Generated by OpenCVE AI on September 17, 2026 at 01:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the Oracle support portal for any security patches or updates that address the authentication bypass vulnerability in Siebel CRM Financial Services versions 17.0–26.7. Apply the patch or update if available.
  • Limit external HTTP access to the application by configuring firewall rules to allow traffic only from trusted IP ranges or through a secure VPN tunnel.
  • Enable detailed application-level logging and monitoring for anomalous login attempts, unauthorized data access, and application crashes, and configure alerts to detect potential exploitation.

Generated by OpenCVE AI on September 17, 2026 at 01:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Access Allows Data Exposure and Denial of Service in Oracle Siebel CRM Financial Services
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel Apps - Financial Services product of Oracle Siebel CRM (component: Financial Accounts). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Financial Services. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel Apps - Financial Services accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel Apps - Financial Services. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).
First Time appeared Oracle
Oracle siebel Apps - Financial Services
CPEs cpe:2.3:a:oracle:siebel_apps_-_financial_services:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Apps - Financial Services
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}


Subscriptions

Oracle Siebel Apps - Financial Services
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T20:04:18.165Z

Reserved: 2026-08-31T15:40:57.346Z

Link: CVE-2026-83197

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:31.167

Modified: 2026-09-16T19:36:43.087

Link: CVE-2026-83197

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T02:00:10Z

Weaknesses