Executive brief
Oracle Siebel CRM is a customer relationship management system used to manage sales and customer interactions. A vulnerability in the Open UI component allows an authenticated attacker with user interaction to compromise the system, resulting in unauthorized access to or modification of customer data and business records.
Technical details
This is a cross-site scripting or similar injection vulnerability in the Open UI component of Oracle Siebel CRM End User. The vulnerability requires low privilege network access via HTTPS and user interaction (such as clicking a malicious link), making it difficult to exploit directly. An attacker can achieve unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to all Siebel CRM End User accessible data. The vulnerability has scope change impact, meaning successful exploitation may significantly affect other connected products or systems. Affected versions are 17.0 through 26.6.
Affected products
- Oracle Siebel CRM End User 17.0 through 26.6
Timeline
- 2026-08-18: disclosed
- 2026-08-18: advisory