ZeroHour

CVE-2026-83203

moderate

Unauthenticated Critical Data Access Flaw in Oracle Siebel CRM Open UI

CVSS 3.1
8.6 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83203 is a high-severity vulnerability in the Open UI component of Oracle Siebel CRM (End User product) affecting versions 17.0 through 26.7. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges or user interaction. A successful attack can result in unauthorized access to critical data — or complete access to all Siebel CRM End User accessible data — as well as unauthorized update, insert, or delete access to some data and a partial denial of service. Any organization running a supported Siebel CRM release in the affected range with an internet-reachable or network-accessible Open UI endpoint is at risk. No public proof-of-concept exists and the flaw is not on the CISA KEV list, so exploitation is not currently observed.

What to do: Apply the Oracle Critical Patch Update that addresses this CVE and upgrade affected Siebel CRM 17.0-26.7 environments to the fixed release. Restrict network access to Siebel Open UI endpoints (VPN, IP allowlisting, or reverse proxy/WAF) so unauthenticated HTTP requests from the internet cannot reach them. Review access and application logs for unauthenticated data access or unexpected insert/update/delete activity, and validate that only authenticated, authorized users can reach the End User application.

Affected
Oracle Siebel CRM (End User, component: Open UI)17.0-26.7
Estimated exposure
moderateestimated few thousand internet-exposed Siebel Open UI instances, within tens of thousands of enterprise deployments overall — Siebel CRM is a large-enterprise on-premises application typically deployed behind firewalls, so only a fraction of the customer base exposes Open UI directly to the internet; public scan data for exposed Siebel web endpoints is typically…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM End User. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM End User accessible data as well as unauthorized update, insert or delete access to some of Siebel CRM End User accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM End User. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

In the news

No ingested article mentions this CVE yet.