ZeroHour

CVE-2026-83146

moderate

User-Interaction Data Theft and Tampering Flaw in Oracle Siebel CRM Open UI

CVSS 3.1
7.7 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83146 is a difficult-to-exploit vulnerability (CVSS 3.1: 7.7, high) in the Open UI component of Oracle Siebel CRM End User, affecting supported versions 17.0 through 26.7. A low-privileged attacker with network access over HTTP must induce an authorized user to interact (for example, via crafted web content or a social-engineering step) in order to compromise the Siebel CRM End User application. Successful attacks can grant unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to all data reachable through Siebel CRM End User, and because the vulnerability has a scope change, successful attacks may also significantly impact additional products beyond Siebel itself. Organizations running supported Siebel CRM releases from 17.0 to 26.7 with Open UI exposed to users over HTTP are affected. There is no known public proof of concept, the flaw is not on the CISA Known Exploited Vulnerabilities list, and no active exploitation has been reported.

What to do: Apply the Oracle Critical Patch Update that delivers the fix for this CVE and move to a Siebel CRM release outside the affected 17.0-26.7 range as soon as the patched build is available from Oracle. In the interim, restrict network exposure of Open UI endpoints (VPN/allowlisting), enforce least-privilege roles for low-privileged accounts, and brief users on avoiding interaction with unsolicited links or content that targets Siebel sessions. Review audit logs for anomalous data modification or access by low-privileged End User accounts.

Affected
Oracle Siebel CRM End User (component: Open UI)17.0 - 26.7 (supported versions)
Estimated exposure
moderateroughly low thousands of enterprise Siebel deployments, potentially serving hundreds of thousands of end users (estimate) — Siebel CRM is deployed almost exclusively at large enterprises (financial services, pharma, telecom) rather than as mass-market software, and public internet scans typically show only a small subset of Open UI endpoints exposed, since most…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM End User. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel CRM End User, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM End User accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM End User accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.