CVE-2026-60591: Critical severity Oracle Oracle Hospitality Simphony vulnerability
Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS). Supported versions that are affected are 19.8-19.8.5, 19.9-19.9.3 and 19.10-19.10.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hospitality Simphony accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hospitality Simphony. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle Hospitality Simphony (Oracle Food and Beverage Applications) - POSto a version that resolves this vulnerability.Fixed in 19.8-19.8.5 - Upgrade
Upgrade
Oracle Hospitality Simphony (Oracle Food and Beverage Applications) - POSto a version that resolves this vulnerability.Fixed in 19.9-19.9.3 - Upgrade
Upgrade
Oracle Hospitality Simphony (Oracle Food and Beverage Applications) - POSto a version that resolves this vulnerability.Fixed in 19.10-19.10.1
Event History
Frequently Asked Questions
Which deployments are affected?
Affected supported versions are 19.8 through 19.8.5, 19.9 through 19.9.3, and 19.10 through 19.10.1 of the POS component of Oracle Hospitality Simphony.
Does exploitation require an account or user interaction?
No. An unauthenticated attacker can exploit the issue over HTTP with network access, and no user interaction is required.
What could a successful attacker do?
A successful attack can create, delete, or modify critical data or all data accessible to Oracle Hospitality Simphony. It can also cause the application to hang or repeatedly crash, resulting in complete denial of service.