Executive brief
Oracle Retail Xstore Point of Service is a retail management system used for processing sales and managing store operations. A vulnerability in the mobile component allows an individual with existing low-level access to the underlying system to view sensitive data they should not be able to see. This could lead to the unauthorized disclosure of business or customer information, though it does not allow the attacker to modify data or shut down the system.
Technical details
A vulnerability in the Xstore Mobile component of Oracle Retail Xstore Point of Service (version 21.0.3) allows for unauthorized data disclosure. The flaw is classified as easily exploitable but requires the attacker to have local logon credentials to the infrastructure where the application is executing. Successful exploitation results in a loss of confidentiality, allowing the attacker to read a subset of data accessible to the service. The vulnerability does not impact data integrity or system availability. This issue was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Retail Xstore Point of Service 21.0.3
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory