Description
Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera). Supported versions that are affected are 5.6.19.23, 5.6.25.17, 5.6.26.10 and 5.6.27.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5 Property Services. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hospitality OPERA 5 Property Services, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality OPERA 5 Property Services accessible data as well as unauthorized read access to a subset of Oracle Hospitality OPERA 5 Property Services accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
Published: 2026-01-20
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Manipulation and Disclosure
Action: Apply Patch
AI Analysis

Impact

The vulnerability in Oracle Hospitality OPERA 5 Property Services permits an unauthenticated attacker with HTTP access to modify, insert, or delete data, as well as read restricted data. The flaw lies in missing or ineffective authorization controls, allowing unauthorized data operations that compromise confidentiality and integrity of hotel management information. Successful exploitation could alter booking records, customer details, or pricing, potentially disrupting operations and exposing sensitive information.

Affected Systems

Oracle Hospitality OPERA 5 Property Services, versions 5.6.19.23, 5.6.25.17, 5.6.26.10 and 5.6.27.4. These deliverables are used by hotels and hospitality establishments to manage reservations and property services.

Risk and Exploitability

The CVSS 3.1 base score of 6.1 indicates a medium severity. The EPSS score is below 1 %, implying a very low but non‑zero probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attack requires an attacker to be on the same network as the OPERA server and to interact through HTTP; user interface interaction is necessary, suggesting the exploit must involve a user delivering a crafted HTTP request. Once activated, the attacker can abuse missing authorization to gain read or write access to a subset of the system’s data. The scope change indicates that impact may extend beyond the OPERA application to other integrated services.

Generated by OpenCVE AI on April 18, 2026 at 04:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check with Oracle for an official patch or update for OPERA 5 Property Services and apply it as soon as possible
  • If a patch is unavailable, restrict HTTP access to the OPERA servers to trusted internal hosts or VPNs, denying public network exposure
  • Configure network firewalls to block unused ports and enforce time‑locked access windows for maintenance

Generated by OpenCVE AI on April 18, 2026 at 04:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 18 Apr 2026 04:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Authorization Bypass in Oracle Hospitality OPERA 5 Property Services
Weaknesses CWE-285

Thu, 29 Jan 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Oracle hospitality Opera 5
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:oracle:hospitality_opera_5:5.6.19.23:*:*:*:*:*:*:*
cpe:2.3:a:oracle:hospitality_opera_5:5.6.25.17:*:*:*:*:*:*:*
cpe:2.3:a:oracle:hospitality_opera_5:5.6.26.10:*:*:*:*:*:*:*
cpe:2.3:a:oracle:hospitality_opera_5:5.6.27.4:*:*:*:*:*:*:*
Vendors & Products Oracle hospitality Opera 5

Wed, 21 Jan 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 20 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera). Supported versions that are affected are 5.6.19.23, 5.6.25.17, 5.6.26.10 and 5.6.27.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5 Property Services. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hospitality OPERA 5 Property Services, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality OPERA 5 Property Services accessible data as well as unauthorized read access to a subset of Oracle Hospitality OPERA 5 Property Services accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
First Time appeared Oracle
Oracle hospitality Opera 5 Property Services
CPEs cpe:2.3:a:oracle:hospitality_opera_5_property_services:5.6.19.23:*:*:*:*:*:*:*
cpe:2.3:a:oracle:hospitality_opera_5_property_services:5.6.25.17:*:*:*:*:*:*:*
cpe:2.3:a:oracle:hospitality_opera_5_property_services:5.6.26.10:*:*:*:*:*:*:*
cpe:2.3:a:oracle:hospitality_opera_5_property_services:5.6.27.4:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hospitality Opera 5 Property Services
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Oracle Hospitality Opera 5 Hospitality Opera 5 Property Services
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-01-21T19:54:47.033Z

Reserved: 2026-01-05T18:07:34.714Z

Link: CVE-2026-21966

cve-icon Vulnrichment

Updated: 2026-01-21T19:54:35.863Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-20T22:15:59.607

Modified: 2026-01-29T14:48:47.800

Link: CVE-2026-21966

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T04:30:35Z

Weaknesses