Junglewise Threat Intelligence

CVE-2026-83217: Oracle Siebel CRM End User auth bypass in Open UI

CVE-2026-83217 · Severity: high · CVSS 7.1 · Published 2026-09-15

Technologies: Oracle Siebel CRM End User. Vendors: Oracle.

Executive brief

Oracle Siebel CRM End User is a customer relationship management platform used by enterprises to manage sales, service, and customer interactions. A vulnerability in the Open UI component allows low-privileged network attackers to read sensitive customer and business data or modify records without proper authorization, potentially exposing confidential information or corrupting critical business data.

Technical details

This is an authorization bypass or privilege escalation vulnerability in the Open UI component of Oracle Siebel CRM End User. The vulnerability is easily exploitable by a low-privileged attacker with network access over HTTP, requiring no user interaction. Successful exploitation grants unauthorized read access to critical data and unauthorized write/delete access to some accessible data. The vulnerability affects versions 17.0 through 26.7. A patch or mitigation is likely available from Oracle; consult the official security bulletin for remediation details.

Affected products

  • Oracle Siebel CRM End User 17.0-26.7

Timeline

  • 2026-09-15: disclosed

References

Related threats