ZeroHour

CVE-2026-83217

moderate

Authenticated Data Access Flaw in Oracle Siebel CRM Open UI (17.0–26.7)

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83217 is a vulnerability in the Open UI component of Oracle Siebel CRM (End User product) affecting supported versions 17.0 through 26.7. A remote attacker who already holds a low-privileged account on the application can exploit it over HTTP with no user interaction, and Oracle rates it as easily exploitable. A successful attack compromises the Siebel CRM End User application, giving the attacker unauthorized read access to critical data — potentially all data reachable through End User — as well as unauthorized update, insert, or delete access to some of that data. The flaw scores 7.1 (High) on CVSS 3.1 with high confidentiality and low integrity impact and no availability impact. There is no known public proof of concept and no indication of in-the-wild exploitation; it was fixed via Oracle's Critical Patch Update process.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83217 to all Siebel CRM 17.0–26.7 environments, prioritizing any Open UI endpoints reachable from the internet or partner networks. Restrict Open UI exposure with a VPN, IP allowlisting, or reverse-proxy authentication, and audit low-privileged user roles for over-broad access. Review application logs for anomalous bulk reads or unexpected update/insert/delete activity by low-privilege accounts.

Affected
Oracle Siebel CRM (End User product, Open UI component)17.0-26.7
Estimated exposure
moderateroughly 1,000–10,000 internet-exposed Siebel Open UI endpoints, within a total base of tens of thousands of mostly internal enterprise deployments — Siebel CRM is an enterprise on-premises CRM concentrated in large organizations, and public internet scan services (Shodan/Censys) have historically shown only low-thousands of exposed Siebel/Open UI login endpoints, so the internet-facing…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM End User. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM End User accessible data as well as unauthorized update, insert or delete access to some of Siebel CRM End User accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.