Description
Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS). Supported versions that are affected are 19.8-19.8.5, 19.9-19.9.3 and 19.10-19.10.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Simphony accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-08-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated remote vulnerability in Oracle Hospitality Simphony enables an attacker with network access to the HTTP interface to retrieve critical data. The flaw requires no credentials and can be leveraged simply by sending a crafted request over the network. Upon exploitation, the attacker can read information exposed by the application, resulting in a confidentiality compromise without affecting integrity or availability.

Affected Systems

Oracle Hospitality Simphony, part of Oracle Food and Beverage Applications, is affected in the following supported versions: 19.8 through 19.8.5, 19.9 through 19.9.3, and 19.10 through 19.10.1.

Risk and Exploitability

The CVSS 3.1 base score of 7.5 indicates a high severity, driven by the lack of authentication, strong network access (AV:N), and low effort to attack (AC:L). The EPSS score of < 1% reflects a very low probability of exploitation, while the vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the flaw over the public or internal network via HTTP, making the risk of exploitation high if the system is exposed without proper segmentation or access controls.

Generated by OpenCVE AI on August 21, 2026 at 17:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch to upgrade to a non‑affected version of Oracle Hospitality Simphony.
  • Block or restrict HTTP access to the Simphony endpoints so that only trusted internal hosts can reach them, using firewalls or reverse‑proxy ACLs.
  • Ensure that all HTTP endpoints that expose sensitive data enforce authentication and proper access controls to prevent unauthenticated access.
  • Review log settings to detect unusual HTTP requests aimed at data extraction and configure alerts accordingly.

Generated by OpenCVE AI on August 21, 2026 at 17:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Exfiltration in Oracle Hospitality Simphony

Fri, 21 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Data Disclosure in Oracle Hospitality Simphony
Weaknesses CWE-200
CWE-287
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 18 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Data Disclosure in Oracle Hospitality Simphony
Weaknesses CWE-200
CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS). Supported versions that are affected are 19.8-19.8.5, 19.9-19.9.3 and 19.10-19.10.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Simphony accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle hospitality Simphony
CPEs cpe:2.3:a:oracle:hospitality_simphony:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hospitality Simphony
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Hospitality Simphony
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T17:24:18.345Z

Reserved: 2026-07-08T15:51:40.546Z

Link: CVE-2026-60590

cve-icon Vulnrichment

Updated: 2026-08-20T17:24:07.092Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:38.367

Modified: 2026-09-04T13:17:33.590

Link: CVE-2026-60590

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T18:00:16Z

Weaknesses