Description
Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS). Supported versions that are affected are 19.8-19.8.5, 19.9-19.9.3 and 19.10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Simphony. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Hospitality Simphony, part of Oracle Food and Beverage Applications, contains a point‑of‑sale component that has an unauthenticated remote code execution vulnerability. The flaw, identified as CWE‑306 (Missing Authentication for Critical Function), permits an attacker with network access over HTTP to perform unauthorized operations. If successfully exploited, the attacker can take full control of the Simphony instance, compromising confidentiality, integrity, and availability of the point‑of‑sale system.

Affected Systems

The vulnerability affects Oracle Hospitality Simphony deployments that are part of Oracle Food and Beverage Applications. Supported affected versions are 19.8 through 19.8.5, 19.9 through 19.9.3, and the 19.10 release. These systems are typically used as point‑of‑sale solutions in restaurants, hotels, resorts, and other hospitality venues.

Risk and Exploitability

The CVSS base score of 8.1 denotes a high severity flaw. The attack vector is network‑based, with no authentication or user interaction required. The EPSS score is less than 1%, indicating a low probability of active exploitation at present, but no confirmation of exploitation is reported in the CISA KEV catalog. The asymmetry of impact—full takeover of Simphony—makes mitigating the flaw a priority even if active exploitation is currently rare.

Generated by OpenCVE AI on August 5, 2026 at 02:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch or upgrade to a post‑19.10 release that includes the fix.
  • Restrict HTTP access to the Simphony servers by implementing network segmentation or firewall rules, limiting inbound traffic to trusted internal sources.
  • Enable logging and monitoring of HTTP requests to the Simphony endpoints, and review logs for abnormal patterns that may indicate exploitation attempts.

Generated by OpenCVE AI on August 5, 2026 at 02:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via HTTP in Oracle Hospitality Simphony

Tue, 28 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Full Takeover of Oracle Hospitality Simphony
Weaknesses CWE-284
CWE-287

Fri, 24 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Full Takeover of Oracle Hospitality Simphony
Weaknesses CWE-284
CWE-287

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS). Supported versions that are affected are 19.8-19.8.5, 19.9-19.9.3 and 19.10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Simphony. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle hospitality Simphony
CPEs cpe:2.3:a:oracle:hospitality_simphony:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:hospitality_simphony:19.10:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hospitality Simphony
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Hospitality Simphony
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T19:33:40.454Z

Reserved: 2026-07-08T15:51:40.517Z

Link: CVE-2026-60169

cve-icon Vulnrichment

Updated: 2026-07-23T19:33:31.309Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T02:15:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function