Executive brief
Oracle Siebel CRM is a customer relationship management platform used to manage customer interactions and business data. An unauthenticated attacker can exploit a vulnerability in the Open UI component via network access to read sensitive customer data, modify or delete records, and temporarily disrupt service availability. This could expose customer information, compromise data integrity, and impact business operations.
Technical details
The vulnerability is an authentication bypass in the Open UI component of Oracle Siebel CRM that allows unauthenticated attackers with network access to send HTTP requests and compromise the system. The flaw permits unauthorized reading of critical data, modification or deletion of certain records, and partial denial of service. No authentication or user interaction is required to exploit this vulnerability. The affected versions are 17.0 through 26.7, and patches are expected from Oracle.
Affected products
- Oracle Siebel CRM End User 17.0-26.7
Timeline
- 2026-09-15: disclosed