Description
Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS). Supported versions that are affected are 19.8-19.8.5, 19.9-19.9.3 and 19.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hospitality Simphony accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hospitality Simphony. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).
Published: 2026-07-21
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle Hospitality Simphony permits any unauthenticated user to reach the system through HTTP and create, delete, or modify critical data, while also triggering crashes that can cause a hang or repeated service interruptions. The vulnerability results in high impact to both data integrity and service availability, reflecting a classic improper access control weakness.

Affected Systems

Oracle Corporation’s Oracle Hospitality Simphony – affected versions include 19.8 through 19.8.5, 19.9 through 19.9.3, and 19.10.

Risk and Exploitability

The CVSS 3.1 base score of 9.1 denotes high severity, yet the EPSS score of less than 1 % indicates a low current exploitation likelihood; the vulnerability is not listed in the CISA KEV catalog. Attackers require only network access to exposed HTTP endpoints and no authentication, making the flaw theoretically easily exploitable, though it is not widely abused in practice.

Generated by OpenCVE AI on August 4, 2026 at 04:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch released in the 2026 July CPU – see the Oracle security alert for the updated Simphony version.
  • Restrict HTTP access to the POS system to trusted IP ranges or enforce VPN access to limit unauthenticated exposure.
  • Monitor Simphony logs for abnormal HTTP traffic or unauthorized data modifications, and investigate promptly.

Generated by OpenCVE AI on August 4, 2026 at 04:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Data Manipulation and Denial of Service in Oracle Hospitality Simphony

Mon, 03 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Data Manipulation and Denial of Service in Oracle Hospitality Simphony
Weaknesses CWE-284

Thu, 30 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Data Manipulation and Denial of Service in Oracle Hospitality Simphony
Weaknesses CWE-284

Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit Allows Data Modification and Service Disruption in Oracle Hospitality Simphony
Weaknesses CWE-284

Fri, 24 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit Allows Data Modification and Service Disruption in Oracle Hospitality Simphony
Weaknesses CWE-284

Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS). Supported versions that are affected are 19.8-19.8.5, 19.9-19.9.3 and 19.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hospitality Simphony accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hospitality Simphony. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).
First Time appeared Oracle
Oracle hospitality Simphony
CPEs cpe:2.3:a:oracle:hospitality_simphony:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:hospitality_simphony:19.10:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hospitality Simphony
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

Oracle Hospitality Simphony
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:06:52.906Z

Reserved: 2026-07-08T15:51:40.516Z

Link: CVE-2026-60168

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:00:05Z

Weaknesses

No weakness.