Executive brief
A security vulnerability has been identified in Oracle Retail EFTLink, a middleware solution used to connect point-of-sale systems with payment terminals. An attacker could remotely access the system to view, modify, or delete sensitive retail and payment-related data. While the attack is difficult to execute, a successful exploit could lead to a significant breach of transaction integrity and data confidentiality.
Technical details
This vulnerability affects the Core/Plugin component of Oracle Retail EFTLink versions 21.0.0 through 25.0.0. It is classified as a high-complexity attack (AC:H) that can be initiated by an unauthenticated attacker over the network via HTTPS. Successful exploitation allows for unauthorized creation, deletion, or modification of critical data, as well as complete unauthorized access to all data accessible by the EFTLink service. The vulnerability impacts confidentiality and integrity but does not directly impact service availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Retail EFTLink 21.0.0 - 25.0.0
Timeline
- 2026-07-21: advisory: Initial publication by Oracle and NVD