Vulnerability in Oracle Siebel CRM End User Component
CVE-2026-70857

7.7HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-70857?

A security flaw in the Oracle Siebel CRM End User product, particularly within the Open UI component, allows low-privileged attackers with network access via HTTPS to potentially compromise the system. Exploiting this vulnerability necessitates human interaction from a third party, hence making it challenging to exploit. Although the vulnerability is localized in the Siebel CRM End User component, successful attacks may have a broader impact on associated products, leading to unauthorized creation, deletion, or modification of sensitive data. Attackers could gain unauthorized access to critical data accessible via the Siebel CRM End User interface, posing a significant risk to information security.

Affected Version(s)

Siebel CRM End User 17.0 <= 26.6

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.