ZeroHour

CVE-2026-83154

moderate

Unauthenticated SOAP Data Access Flaw in Oracle Siebel CRM Open UI

CVSS 3.1
9.1 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-83154 is a critical (CVSS 9.1) vulnerability in the Open UI component of Oracle Siebel CRM's End User product, affecting all supported versions from 17.0 through 26.7. It is easily exploitable by an unauthenticated attacker with network access who can reach the product's SOAP interface, requiring no privileges or user interaction. A successful attack lets the attacker create, delete, or modify critical data — or all data accessible to the Siebel CRM End User application — as well as read that data in full, with high impacts on both confidentiality and integrity (availability is not affected). Any organization running Siebel CRM within the affected version range with a network-reachable SOAP endpoint is exposed, particularly if the service is internet-facing. The flaw is not currently listed in CISA's KEV catalog, no public proof-of-concept is known, and no exploitation in the wild has been reported.

What to do: Apply the Oracle Critical Patch Update that fixes CVE-2026-83154 for your Siebel Innovation Release, or upgrade to a release later than 26.7 (e.g., 26.8+). Restrict and segment network access to Siebel SOAP/EAI web service endpoints so they are not reachable from untrusted networks such as the internet. Review application and web server logs for unauthenticated SOAP requests, unexpected record creation/deletion, or anomalous data modifications that could indicate prior probing or compromise.

Affected
Oracle Siebel CRM (End User product, Open UI component)17.0-26.7
Estimated exposure
moderateLow thousands of internet-exposed Siebel installations; tens of thousands of enterprise deployments overall — Siebel CRM is an on-premises enterprise product concentrated in large organizations, and internet-wide scans typically surface only a few thousand externally reachable Siebel application/SOAP endpoints, with most deployments keeping web…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Siebel CRM End User. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM End User accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM End User accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.