Executive brief
Oracle Hospitality OPERA 5 is a property management platform used by hotels and resorts to manage reservations, guest services, and financial operations. A critical security flaw allows an unauthorized person to remotely take full control of the system over the internet without needing a password. This could lead to the theft of sensitive guest data, disruption of hotel operations, and complete loss of system integrity.
Technical details
A critical vulnerability exists in the Opera component of Oracle Hospitality OPERA 5 Property Services. The flaw is characterized by a low attack complexity and requires no authentication or user interaction, making it easily exploitable over the network via HTTP. While the specific vulnerability class (e.g., RCE, auth bypass) is not explicitly named in the advisory, the impact is defined as a complete takeover of the application, affecting confidentiality, integrity, and availability. Affected versions include 5.6.19.24, 5.6.22, 5.6.25.19, 5.6.27.6, and 5.6.28. Users are advised to refer to the Oracle Critical Patch Update for remediation steps.
Affected products
- Oracle Hospitality OPERA 5 Property Services 5.6.19.24, 5.6.22, 5.6.25.19, 5.6.27.6, 5.6.28
Timeline
- 2026-05-28: disclosed: Initial publication of the CVE record.
- 2026-05-28: advisory: Oracle security alert published.