CVE-2026-71106: High severity Oracle Oracle Hospitality OPERA 5 Property Services vulnerability
Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera Servlet). Supported versions that are affected are 5.6.28.0-5.6.28.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5 Property Services. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Hospitality OPERA 5 Property Services. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.6.28.0-5.6.28.1
Event History
Frequently Asked Questions
Which deployments are affected?
Affected supported versions are Oracle Hospitality OPERA 5 Property Services 5.6.28.0 through 5.6.28.1, specifically the Opera Servlet component.
What access does an attacker need?
An attacker does not need authentication or prior privileges. They need network access to the affected service via HTTP and must induce interaction by someone other than the attacker.
What is the potential impact of successful exploitation?
Successful exploitation can result in takeover of Oracle Hospitality OPERA 5 Property Services, with high confidentiality, integrity, and availability impact.