Executive brief
Oracle Retail Xstore Point of Service is a retail management system used for processing sales and managing store operations. A vulnerability in the Xstore Mobile component allows an authorized user with low-level permissions to gain unauthorized access to certain sensitive data. This could lead to the exposure of business or customer information, though it does not allow for full system takeover or service disruption.
Technical details
An information disclosure vulnerability exists in the Xstore Mobile component of Oracle Retail Xstore Point of Service version 21.0.3. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows the attacker to gain unauthorized read access to a subset of data within the application. The vulnerability has a CVSS 3.1 base score of 4.3, reflecting a limited impact on confidentiality with no impact on integrity or availability. Users should refer to the Oracle July 2026 Critical Patch Update for remediation details.
Affected products
- Oracle Retail Xstore Point of Service 21.0.3
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory