Junglewise Threat Intelligence

CVE-2026-21954: Oracle Retail Xstore Point of Service Information Disclosure in Xstore Mobile

CVE-2026-21954 · Severity: medium · CVSS 4.3 · Published 2026-07-21

Vendors: Oracle.

Executive brief

Oracle Retail Xstore Point of Service is a retail management system used for processing sales and managing store operations. A vulnerability in the Xstore Mobile component allows an authorized user with low-level permissions to gain unauthorized access to certain sensitive data. This could lead to the exposure of business or customer information, though it does not allow for full system takeover or service disruption.

Technical details

An information disclosure vulnerability exists in the Xstore Mobile component of Oracle Retail Xstore Point of Service version 21.0.3. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows the attacker to gain unauthorized read access to a subset of data within the application. The vulnerability has a CVSS 3.1 base score of 4.3, reflecting a limited impact on confidentiality with no impact on integrity or availability. Users should refer to the Oracle July 2026 Critical Patch Update for remediation details.

Affected products

  • Oracle Retail Xstore Point of Service 21.0.3

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats