Executive brief
Oracle Siebel CRM is a customer relationship management platform used by enterprises to manage sales, service, and marketing operations. A vulnerability in the Open UI component allows unauthenticated attackers to remotely compromise the system and take over CRM End User installations, potentially exposing sensitive customer and business data or disrupting business operations.
Technical details
This is a difficult-to-exploit remote vulnerability in the Siebel CRM End User Open UI component affecting versions 17.0 through 26.7. The flaw allows unauthenticated attackers with network access via HTTP to achieve full system compromise, resulting in takeover of the affected Siebel CRM End User instance. No authentication or user interaction is required for exploitation. The exact technical mechanism is not publicly disclosed; however, the high CVSS score and impact severity suggest a critical control bypass or code execution weakness. Oracle has issued a security advisory identifying this flaw.
Affected products
- Oracle Siebel CRM End User 17.0 through 26.7
Timeline
- 2026-09-15: disclosed