Description
Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS). Supported versions that are affected are 19.8-19.8.5, 19.9-19.9.3 and 19.10-19.10.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Simphony accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-08-18
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated remote vulnerability in Oracle Hospitality Simphony allows an attacker with network access to the HTTP interface to retrieve critical data. The flaw requires no credentials and can be leveraged simply by sending a crafted request over the network. Once exploited, the attacker can read information exposed by the application, resulting in a confidentiality compromise without affecting integrity or availability.

Affected Systems

Oracle Hospitality Simphony, part of Oracle Food and Beverage Applications, is affected in the following supported versions: 19.8 through 19.8.5, 19.9 through 19.9.3, and 19.10 through 19.10.1.

Risk and Exploitability

The CVSS 3.1 base score of 7.5 indicates a high severity, driven by the lack of authentication, strong network access (AV:N), and low effort to attack (AC:L). The EPSS score is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the flaw over the public or internal network via HTTP, making the risk of exploitation high if the system is exposed without proper network segmentation or access controls.

Generated by OpenCVE AI on August 18, 2026 at 23:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch or upgrade to a non‑affected version of Oracle Hospitality Simphony.
  • Block or restrict HTTP access to the Simphony endpoints only to trusted internal hosts using firewalls or reverse‑proxy ACLs.
  • Enable and enforce authentication for all HTTP endpoints that expose sensitive data, or otherwise enforce proper access controls to prevent unauthenticated access.

Generated by OpenCVE AI on August 18, 2026 at 23:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Data Disclosure in Oracle Hospitality Simphony
Weaknesses CWE-200
CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS). Supported versions that are affected are 19.8-19.8.5, 19.9-19.9.3 and 19.10-19.10.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Simphony accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle hospitality Simphony
CPEs cpe:2.3:a:oracle:hospitality_simphony:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hospitality Simphony
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Hospitality Simphony
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:58:55.922Z

Reserved: 2026-07-08T15:51:40.546Z

Link: CVE-2026-60590

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:38.367

Modified: 2026-08-18T21:16:38.367

Link: CVE-2026-60590

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T23:15:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-287

    Improper Authentication