Description
Vulnerability in the Siebel Apps - Self Service product of Oracle Siebel CRM (component: Helpdesk/Training). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps - Self Service. Successful attacks of this vulnerability can result in takeover of Siebel Apps - Self Service. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote System Takeover
Action: Assess Impact
AI Analysis

Impact

A flaw in the Helpdesk/Training component of Oracle Siebel Apps - Self Service permits a low-privileged attacker who can reach the application via HTTP to assume full control of the system. The vulnerability, classified as CWE-269, allows compromise of confidentiality, integrity, and availability with a single successful request.

Affected Systems

Oracle Corporation’s Siebel Apps - Self Service is affected. Versions spanning 17.0 up to and including 26.7 contain the vulnerable Helpdesk/Training module. No newer version or patch was indicated in the provided data, so all instances within that range remain at risk until a vendor resolution is applied.

Risk and Exploitability

With a CVSS 3.1 base score of 8.8 the vulnerability is high severity. The EPSS score is less than 1%, indicating a low probability of exploitation at present, and the flaw is not catalogued in CISA's KEV. The vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) shows exploitation requires only network access over HTTP, low attack complexity, and low privileges, with no user interaction. An attacker satisfying those conditions can gain complete control of the Self Service instance, exposing all stored customer data and internal processes.

Generated by OpenCVE AI on September 20, 2026 at 08:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any available Oracle patch or upgrade the Siebel Apps - Self Service installation to a version beyond 26.7 to eliminate the vulnerability.
  • Restrict incoming HTTP traffic to the Self Service instance so that only trusted administrative IP ranges can reach it, reducing the likelihood of a low-privilege attacker reaching the vulnerable component.
  • Review and enforce least-privilege role definitions for the Helpdesk/Training component, ensuring users and services have only the access required to perform their duties.

Generated by OpenCVE AI on September 20, 2026 at 08:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Access Allows Full System Takeover in Oracle Siebel Apps - Self Service

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Remote Low‑Privilege Attack Allows System Takeover in Siebel Apps – Self Service
Weaknesses CWE-284
CWE-285

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Title Remote Low‑Privilege Attack Allows System Takeover in Siebel Apps – Self Service
Weaknesses CWE-284
CWE-285

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel Apps - Self Service product of Oracle Siebel CRM (component: Helpdesk/Training). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps - Self Service. Successful attacks of this vulnerability can result in takeover of Siebel Apps - Self Service. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle siebel Apps - Self Service
CPEs cpe:2.3:a:oracle:siebel_apps_-_self_service:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Apps - Self Service
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Siebel Apps - Self Service
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:10:41.515Z

Reserved: 2026-08-31T15:40:57.347Z

Link: CVE-2026-83212

cve-icon Vulnrichment

Updated: 2026-09-17T13:01:35.810Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:32.860

Modified: 2026-09-17T14:17:36.530

Link: CVE-2026-83212

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T09:00:13Z

Weaknesses
  • CWE-269

    Improper Privilege Management