Description
Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). The supported version that is affected is 21.0.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Retail Xstore Point of Service accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-07-21
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle Retail Xstore Point of Service 21.0.3 allows an attacker with low privileges and network connectivity via HTTP to read a limited set of data that should be protected. This occurs due to improper access control, resulting in a confidentiality compromise. The risk of exploitation is moderate, as the required attack vector is openly reachable over HTTP and does not require authentication or elevated privileges.

Affected Systems

Affected system is Oracle Retail Xstore Point of Service (Xstore Mobile) version 21.0.3. The vulnerability is present in the mobile component of the point‑of‑sale application.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate confidentiality impact, and the EPSS score of less than 1% suggests a low probability of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog. Attackers could exploit the open HTTP interface from within the network; no additional privileges are required beyond low privileged access, making local network compromise a likely scenario.

Generated by OpenCVE AI on August 4, 2026 at 05:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Restrict network access to the Xstore service by implementing firewall rules or network segmentation so that only trusted hosts can reach the HTTP interface.
  • Review and tighten the application’s access‑control lists to enforce the principle of least privilege, ensuring that only authorized roles have read access to protected data.
  • Enable detailed logging and continuous monitoring of read operations on sensitive resources to detect and respond to unauthorized access attempts.

Generated by OpenCVE AI on August 4, 2026 at 05:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Read Access in Oracle Retail Xstore Point of Service

Sat, 01 Aug 2026 07:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Read Access Vulnerability in Oracle Retail Xstore Point of Service 21.0.3

Fri, 24 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Read Access Vulnerability in Oracle Retail Xstore Point of Service 21.0.3

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). The supported version that is affected is 21.0.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Retail Xstore Point of Service accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle retail Xstore Point Of Service
CPEs cpe:2.3:a:oracle:retail_xstore_point_of_service:21.0.3:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle retail Xstore Point Of Service
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Oracle Retail Xstore Point Of Service
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:20:14.432Z

Reserved: 2026-01-05T18:07:34.713Z

Link: CVE-2026-21954

cve-icon Vulnrichment

Updated: 2026-07-23T15:15:01.045Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:17:00.763

Modified: 2026-08-07T20:32:37.367

Link: CVE-2026-21954

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:30:04Z

Weaknesses