Description
Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM End User. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM End User accessible data as well as unauthorized update, insert or delete access to some of Siebel CRM End User accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM End User. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).
Published: 2026-09-15
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data access and partial denial of service
Action: Immediate patch
AI Analysis

Impact

The vulnerability arises within the Open UI component of Oracle Siebel CRM End User and permits an unauthenticated attacker with network access over HTTP to bypass authentication mechanisms. This flaw enables the attacker to read or manipulate critical data, gain full access to all data exposed by the system, or induce a partial denial of service, affecting confidentiality, integrity, and availability as reflected in the high CVSS score.

Affected Systems

Affected customers use Oracle Siebel CRM End User in versions ranging from 17.0 through 26.7. Vendors should verify that any deployments of these versions have not been patched or otherwise mitigated. No specific build numbers are referenced beyond this range.

Risk and Exploitability

The CVSS 3.1 base score of 8.6 indicates a high severity. The EPSS score is listed as less than 1%, which suggests a very low current exploitation probability, but that does not eliminate the risk. The vulnerability is not yet listed in the CISA KEV catalog, though its potential for widespread unauthorized access makes it a significant asset to adversaries. Attackers could target exposed HTTP endpoints to exploit the flaw without authentication or UI interaction, achieving breach or service disruption.

Generated by OpenCVE AI on September 16, 2026 at 21:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch or update released in the 2026 security advisory for Siebel CRM End User.
  • If a patch is not yet available, restrict direct HTTP access to the Siebel CRM End User interface by configuring firewalls, IP whitelisting, or placing the service behind a reverse proxy.
  • Review and enforce least‑privilege access controls for all administrators and users, and monitor logs for anomalous data access patterns.

Generated by OpenCVE AI on September 16, 2026 at 21:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Data Access in Oracle Siebel CRM End User (Open UI)
Weaknesses CWE-284
CWE-287

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM End User. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM End User accessible data as well as unauthorized update, insert or delete access to some of Siebel CRM End User accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM End User. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).
First Time appeared Oracle
Oracle siebel Crm End User
CPEs cpe:2.3:a:oracle:siebel_crm_end_user:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm End User
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L'}


Subscriptions

Oracle Siebel Crm End User
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T20:04:20.054Z

Reserved: 2026-08-31T15:40:57.346Z

Link: CVE-2026-83203

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:31.870

Modified: 2026-09-16T19:36:43.087

Link: CVE-2026-83203

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T22:00:08Z

Weaknesses