Junglewise Threat Intelligence

CVE-2026-34311: Oracle Hospitality OPERA 5 remote takeover in Opera component

CVE-2026-34311 · Severity: critical · CVSS 9.8 · Published 2026-05-28

Vendors: Oracle.

Executive brief

Oracle Hospitality OPERA 5 is a property management platform used by hotels and resorts to manage reservations, guest services, and financial operations. A critical security flaw allows an unauthorized person to remotely take full control of the system over the internet without needing a password. This could lead to the theft of sensitive guest data, disruption of hotel operations, and complete loss of system integrity.

Technical details

A critical vulnerability exists in the Opera component of Oracle Hospitality OPERA 5 Property Services. The flaw is characterized by a low attack complexity and requires no authentication or user interaction, making it easily exploitable over the network via HTTP. While the specific vulnerability class (e.g., RCE, auth bypass) is not explicitly named in the advisory, the impact is defined as a complete takeover of the application, affecting confidentiality, integrity, and availability. Affected versions include 5.6.19.24, 5.6.22, 5.6.25.19, 5.6.27.6, and 5.6.28. Users are advised to refer to the Oracle Critical Patch Update for remediation steps.

Affected products

  • Oracle Hospitality OPERA 5 Property Services 5.6.19.24, 5.6.22, 5.6.25.19, 5.6.27.6, 5.6.28

Timeline

  • 2026-05-28: disclosed: Initial publication of the CVE record.
  • 2026-05-28: advisory: Oracle security alert published.

References

Related threats