Description
Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS). Supported versions that are affected are 19.8-19.8.5, 19.9-19.9.3 and 19.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Simphony accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in the Oracle Hospitality Simphony POS component and is a result of improper authentication and access control weaknesses (CWE-284). An attacker who can reach the Simphony HTTP endpoint does not need credentials and can use the vulnerability to read any data the application handles, effectively bypassing authentication controls and gaining direct, unauthorized access to critical business information.

Affected Systems

Oracle Hospitality Simphony, part of Oracle Food and Beverage Applications, is affected. Versions 19.8 through 19.8.5, 19.9 through 19.9.3, and 19.10 contain the vulnerability. The issue lies in the POS module and applies to any instance exposed to the network.

Risk and Exploitability

The CVSS 3.1 base score of 7.5 indicates moderate‑high severity, primarily impacting confidentiality. The EPSS score of less than 1% shows a very low but non‑zero probability of exploitation under current data. Because the vulnerability is not listed in the CISA KEV catalog, there is no confirmed exploitation evidence. Attackers would need network access to the Simphony HTTP endpoint; no authentication is required, so unauthorized data exposure can occur quickly. Reducing risk requires prompt patching, restricting inbound HTTP traffic, and vigilant monitoring of anomalous requests.

Generated by OpenCVE AI on August 2, 2026 at 23:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Hospitality Simphony patch or upgrade to a version that includes the fix as indicated in Oracle’s July 2026 security advisory.
  • Restrict inbound HTTP traffic to the Simphony service to trusted internal networks or VPNs, preventing direct external exposure.
  • Monitor HTTP logs and traffic for anomalous requests or repeated access attempts, and configure alerts for suspicious activity.

Generated by OpenCVE AI on August 2, 2026 at 23:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access in Oracle Hospitality Simphony Enables Confidential Data Exposure

Tue, 28 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Unauthorized Data Breach in Oracle Hospitality Simphony
Weaknesses CWE-287

Fri, 24 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Unauthorized Data Breach in Oracle Hospitality Simphony
Weaknesses CWE-287

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS). Supported versions that are affected are 19.8-19.8.5, 19.9-19.9.3 and 19.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Simphony accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle hospitality Simphony
CPEs cpe:2.3:a:oracle:hospitality_simphony:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:hospitality_simphony:19.10:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hospitality Simphony
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Hospitality Simphony
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T16:22:37.096Z

Reserved: 2026-07-08T15:51:40.517Z

Link: CVE-2026-60170

cve-icon Vulnrichment

Updated: 2026-07-23T16:22:33.589Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T23:45:03Z

Weaknesses