Description
Vulnerability in the Oracle Retail EFTLink product of Oracle Retail Applications (component: Core/Plugin). Supported versions that are affected are 21.0.0-25.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Retail EFTLink. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Retail EFTLink accessible data as well as unauthorized access to critical data or complete access to all Oracle Retail EFTLink accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a CWE‑284 broken access control flaw that allows an unauthenticated attacker who can reach the Oracle Retail EFTLink service over HTTPS to create, delete, or modify critical data. Because authentication is not required, the attacker can also gain read access to all information that the EFTLink component exposes. The flaw results in significant confidentiality and integrity breaches for any organization running affected versions of the product.

Affected Systems

Oracle Retail EFTLink by Oracle Corporation, versions 21.0.0 through 25.0.0 are affected.

Risk and Exploitability

The CVSS base score of 7.4 and an EPSS score of less than 1% indicate that while the vulnerability is moderately severe, it is not highly likely to be exploited. The flaw is reachable via standard HTTPS traffic, and no authentication is needed, making it a straightforward remote exploitation path for attackers with network access to the EFTLink service. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.

Generated by OpenCVE AI on August 4, 2026 at 05:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Retail EFTLink patch released in the July 2026 CPU, which resolves the broken access control flaw (CWE‑284).
  • Limit inbound HTTPS traffic to EFTLink to trusted IP ranges or internal subnets using firewall or ACL rules, thereby restricting unauthenticated users from exploiting the broken access control.
  • Enforce strict TLS configuration by disabling TLS 1.0/1.1, banning weak cipher suites, and enabling Perfect Forward Secrecy to prevent downgrade tampering.

Generated by OpenCVE AI on August 4, 2026 at 05:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Data Modification and Read in Oracle Retail EFTLink via HTTPS

Sat, 01 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Data Modification and Read in Oracle Retail EFTLink via HTTPS

Wed, 29 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Manipulation of Oracle Retail EFTLink Data Over HTTPS

Fri, 24 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Manipulation of Oracle Retail EFTLink Data Over HTTPS

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Retail EFTLink product of Oracle Retail Applications (component: Core/Plugin). Supported versions that are affected are 21.0.0-25.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Retail EFTLink. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Retail EFTLink accessible data as well as unauthorized access to critical data or complete access to all Oracle Retail EFTLink accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle retail Eftlink
CPEs cpe:2.3:a:oracle:retail_eftlink:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle retail Eftlink
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Retail Eftlink
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:18:20.124Z

Reserved: 2026-05-18T15:55:10.313Z

Link: CVE-2026-46943

cve-icon Vulnrichment

Updated: 2026-07-23T15:14:47.925Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:30:04Z

Weaknesses