Executive brief
Oracle Siebel CRM End User is a customer relationship management platform used by enterprises to manage sales, service, and customer interactions. A vulnerability in the Open UI component allows low-privileged network attackers to read sensitive customer and business data or modify records without proper authorization, potentially exposing confidential information or corrupting critical business data.
Technical details
This is an authorization bypass or privilege escalation vulnerability in the Open UI component of Oracle Siebel CRM End User. The vulnerability is easily exploitable by a low-privileged attacker with network access over HTTP, requiring no user interaction. Successful exploitation grants unauthorized read access to critical data and unauthorized write/delete access to some accessible data. The vulnerability affects versions 17.0 through 26.7. A patch or mitigation is likely available from Oracle; consult the official security bulletin for remediation details.
Affected products
- Oracle Siebel CRM End User 17.0-26.7
Timeline
- 2026-09-15: disclosed