Description
Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Reports). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM End User. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM End User accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Data Exposure
Action: Immediate Patch
AI Analysis

Impact

An unauthenticated attacker who can reach the Siebel CRM End User service via HTTP can exploit a flaw in the Reports component. The vulnerability allows the attacker to read all data that the end‑user application can access, leading to a complete compromise of the confidentiality of critical information stored in the system. The weakness manifests as a lack of proper access control on report generation, enabling arbitrary data retrieval without authentication. This results in a high‑secrecy breach, as described by the CVSS 3.1 vector.

Affected Systems

Oracle Siebel CRM End User, versions 17.0 through 26.7 inclusive, are affected. The vulnerability is present in the Reports component of the product.

Risk and Exploitability

The CVSS Base Score of 7.5 indicates a high impact on confidentiality. The EPSS score is below 1 %, suggesting a low probability of exploitation at the time of analysis, yet the vulnerability is not listed in the CISA KEV catalog. The attack vector is likely an unauthenticated, network‑based exploit over HTTP, given the described conditions. An attacker does not need any privileged credentials and can gain full read access to the data exposed by the component.

Generated by OpenCVE AI on September 21, 2026 at 20:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle Siebel CRM End User patch or upgrade to a version later than 26.7 when it becomes available.
  • Restrict HTTP access to the Reports endpoint to trusted IP ranges or a dedicated firewall zone to reduce exposure.
  • Enable comprehensive logging for report requests and monitor for anomalous activity or repeated failed attempts.
  • If the Reports component is not required for business processes, consider disabling or removing it from the deployment.

Generated by OpenCVE AI on September 21, 2026 at 20:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access to Siebel CRM Reports Grants Full Data Exposure

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Report Read Exposes Sensitive Data in Siebel CRM End User
Weaknesses CWE-263

Mon, 21 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sun, 20 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Report Read Exposes Sensitive Data in Siebel CRM End User
Weaknesses CWE-263

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit in Siebel CRM End User Reports Allows Full Data Access
Weaknesses CWE-200
CWE-284

Wed, 16 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit in Siebel CRM End User Reports Allows Full Data Access
Weaknesses CWE-200
CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Reports). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM End User. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM End User accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle siebel Crm End User
CPEs cpe:2.3:a:oracle:siebel_crm_end_user:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm End User
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Siebel Crm End User
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-21T16:42:31.956Z

Reserved: 2026-08-31T15:40:57.347Z

Link: CVE-2026-83213

cve-icon Vulnrichment

Updated: 2026-09-21T16:42:27.423Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:32.963

Modified: 2026-09-21T17:19:06.590

Link: CVE-2026-83213

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T20:45:17Z

Weaknesses