Sceawere
Vulnerability Detail
CVE-2026-70857UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Siebel CRM Open UI Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.7
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Siebel CRM End User
- Attack Type
- Difficult to exploit vulnerability allows low privileged attacker with network access via HTTPS to compromise Siebel CRM End User. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel CRM End User, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM End User accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM End User accessible data.
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTPS to compromise Siebel CRM End User. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel CRM End User, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM End User accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM End User accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.7",
"pubDate": "2026-08-18T21:17:41.867Z",
"pubdate": "2026-08-18T21:17:41.867Z",
"executiveSummary": "A vulnerability has been identified within the Open UI component of the Oracle Siebel CRM End User product, affecting supported versions 17.0 through 26.6. This security flaw introduces significant risk to organizational data integrity and confidentiality. The vulnerability allows a low-privileged remote attacker with network access via HTTPS to compromise the Siebel CRM End User application.\nSuccessful exploitation of this vulnerability is characterized by a difficult attack vector that requires explicit human interaction from a user other than the attacker. Due to a scope change (S:C), a successful exploit against the Siebel CRM End User component can significantly impact additional integrated or associated products beyond the immediate boundary of the vulnerable application.\nThe primary risk implications involve severe breaches of data security. Attackers who successfully execute an exploit gain unauthorized capabilities to create, delete, or modify critical data, as well as achieve unauthorized or complete access to all data accessible within the Siebel CRM End User environment. The CVSS 3.1 base score is 7.7, reflecting high impacts to both confidentiality and integrity with no availability impact.",
"technicalDetails": "The vulnerability resides in the Open UI component of the Oracle Siebel CRM End User product, impacting versions 17.0 to 26.6. The architectural design of the Open UI layer handles user interface rendering and client-server communication over HTTPS, presenting an attack surface accessible via network vectors.\nExploitation requires the attacker to possess low privileges within the application and network access via the HTTPS protocol. Furthermore, the attack vector exhibits a high attack complexity (AC:H) and strictly necessitates human interaction (UI:R) from a third party, such as a victimized user navigating the application interface while malicious conditions are met.\nThe attack flow begins with the low-privileged attacker preparing a crafted input or interaction vector delivered across the HTTPS protocol to the Siebel CRM End User interface. Because human interaction is required, the attacker typically induces a victim user to interact with the malicious payload or manipulated Open UI component.\nUpon execution, due to the scope change (S:C) characteristic of the vulnerability, the impact extends beyond the Siebel CRM End User security scope to affect additional collateral products or system components. The resulting post-exploitation impact includes unauthorized creation, deletion, and modification of critical application data, alongside comprehensive unauthorized or complete access to all data accessible to the Siebel CRM End User.\nThe vector parameters are defined by CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N, indicating Network attack vector, High attack complexity, Low privileges required, User interaction required, Changed scope, High confidentiality impact, High integrity impact, and None for availability impact."
}