Description
Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). The supported version that is affected is 21.0.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Retail Xstore Point of Service executes to compromise Oracle Retail Xstore Point of Service. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Retail Xstore Point of Service accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-07-21
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Role‑based Access Control flaw (CWE‑284) in the Xstore Mobile component of Oracle Retail Xstore Point of Service. A low‑privileged user who can log on to the infrastructure where the application runs can exploit the weakness. A successful exploit yields read access to a subset of the application’s data, compromising confidentiality but not integrity or availability.

Affected Systems

Oracle Corporation’s Oracle Retail Xstore Point of Service, version 21.0.3, is the only affected release. No other versions are listed as vulnerable.

Risk and Exploitability

The CVSS 3.1 score of 3.3 indicates the threat is low. The EPSS value of less than 1% shows that exploitation is unlikely in the wild. The vulnerability is not listed in CISA’s KEV catalog. Attack requires physical or local network access to the host and a non‑privileged account; once access is achieved, the attacker can read protected data.

Generated by OpenCVE AI on August 4, 2026 at 17:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch for Oracle Retail Xstore Point of Service 21.0.3
  • Limit local logon privileges to only trusted accounts and follow the principle of least privilege
  • Enable and regularly review audit logging to detect unauthorized read attempts

Generated by OpenCVE AI on August 4, 2026 at 17:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title Data Disclosure Vulnerability in Oracle Retail Xstore Point of Service

Wed, 29 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Read Access Vulnerability in Oracle Retail Xstore Point of Service 21.0.3
Weaknesses CWE-200

Fri, 24 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Read Access Vulnerability in Oracle Retail Xstore Point of Service 21.0.3
Weaknesses CWE-200

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). The supported version that is affected is 21.0.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Retail Xstore Point of Service executes to compromise Oracle Retail Xstore Point of Service. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Retail Xstore Point of Service accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle retail Xstore Point Of Service
CPEs cpe:2.3:a:oracle:retail_xstore_point_of_service:21.0.3:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle retail Xstore Point Of Service
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Oracle Retail Xstore Point Of Service
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:20:21.725Z

Reserved: 2026-01-05T18:07:34.713Z

Link: CVE-2026-21953

cve-icon Vulnrichment

Updated: 2026-07-23T15:15:02.858Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:17:00.620

Modified: 2026-08-07T20:19:51.000

Link: CVE-2026-21953

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T18:00:14Z

Weaknesses