CVE-2026-60590: High severity Oracle Oracle Hospitality Simphony vulnerability
Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS). Supported versions that are affected are 19.8-19.8.5, 19.9-19.9.3 and 19.10-19.10.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Simphony accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network access to Oracle Hospitality Simphony POS over HTTP so that unauthenticated remote attackers cannot reach the affected service.
Event History
Frequently Asked Questions
Which deployments are affected?
Affected supported versions are 19.8 through 19.8.5, 19.9 through 19.9.3, and 19.10 through 19.10.1 of the POS component in Oracle Hospitality Simphony.
What does an attacker need to exploit this issue?
An attacker needs network access to the affected product via HTTP. No authentication, privileges, or user interaction are required.
What is the likely impact of successful exploitation?
Successful exploitation can provide unauthorized access to critical data or complete access to all data accessible through Oracle Hospitality Simphony. The stated impact is confidentiality only; integrity and availability impacts are not identified.