Description
Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions that are affected are 25.12-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Exposure
Action: Immediate Patch
AI Analysis

Impact

This vulnerability is an unauthenticated flaw in the Open Integration component of Oracle Siebel CRM that allows an attacker with network access to send HTTP requests and read all data exposed by the integration service. The CVSS 3.1 vector indicates AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N, meaning that confidential information can be disclosed while integrity and availability remain unchanged.

Affected Systems

Oracle’s Siebel CRM Integration product, versions 25.12 through 26.7, is affected. The vulnerability exists in the Open Integration module, which manages integration endpoints accessible over HTTP.

Risk and Exploitability

The CVSS base score of 7.5 denotes a high‑severity condition, yet the EPSS score of less than 1 % suggests that attacks are not yet widespread or detected. The vulnerability is not listed in the CISA KEV catalog. An attacker does not need credentials; unauthenticated HTTP traffic to the vulnerable integration endpoints is sufficient for exploitation when the service is reachable from the network.

Generated by OpenCVE AI on September 20, 2026 at 07:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch for Oracle Siebel CRM Integration versions 25.12–26.7 as detailed in the Oracle security advisory.
  • Restrict HTTP access to the integration service by limiting allowed IP ranges or placing the service behind a firewall or reverse proxy.
  • Configure monitoring and alerting on integration service logs to detect and respond to suspicious or unauthorized access attempts.

Generated by OpenCVE AI on September 20, 2026 at 07:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Leads to Data Exposure in Oracle Siebel CRM Integration
Weaknesses CWE-200
CWE-284

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Full Data Exposure in Oracle Siebel CRM Integration
Weaknesses CWE-200
CWE-284

Thu, 17 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Full Data Exposure in Oracle Siebel CRM Integration
Weaknesses CWE-200
CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions that are affected are 25.12-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle siebel Crm Integration
CPEs cpe:2.3:a:oracle:siebel_crm_integration:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Integration
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Siebel Crm Integration
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-21T19:17:20.602Z

Reserved: 2026-08-31T15:40:57.353Z

Link: CVE-2026-83326

cve-icon Vulnrichment

Updated: 2026-09-21T19:17:16.880Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:45.770

Modified: 2026-09-21T20:17:34.223

Link: CVE-2026-83326

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T07:45:16Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control