ZeroHour

CVE-2026-83192

moderate

Unauthenticated Takeover Vulnerability in Oracle Siebel CRM Open UI (CVE-2026-83192)

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83192 is a difficult-to-exploit, unauthenticated vulnerability in the Open UI component of Oracle Siebel CRM End User, affecting supported versions 17.0 through 26.7. An attacker needs only network access via HTTP — no credentials, privileges, or user interaction — to trigger the flaw, though the high attack complexity means exploitation likely requires timing, race conditions, or special circumstances. A successful attack results in a complete takeover of the Siebel CRM End User application, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 8.1). Organizations running on-premises or hosted Siebel CRM deployments that expose the End User Open UI over the network are affected. There is no known public proof of concept, no evidence of in-the-wild exploitation, and the flaw is not on the CISA Known Exploited Vulnerabilities catalog.

What to do: Apply the Oracle Critical Patch Update (CPU) that addresses this vulnerability as soon as possible if you run Siebel CRM End User versions 17.0-26.7. Until patched, restrict network access to Open UI endpoints via IP allowlisting or VPN and ensure the application is not directly internet-facing. Review HTTP access logs for anomalous unauthenticated requests to the Open UI component and monitor for unexpected administrative changes or data access.

Affected
Oracle Siebel CRM End User (Open UI component)17.0-26.7
Estimated exposure
moderate≈ low thousands of internet-exposed Siebel Open UI endpoints, plus a larger internal/VPN-only install base likely in the tens of thousands of deployments — Siebel CRM is a legacy enterprise product with no public install counts, but public internet scans historically show a few thousand exposed Open UI endpoints, with most deployments internal-facing behind perimeters.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM End User. Successful attacks of this vulnerability can result in takeover of Siebel CRM End User. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.