Junglewise Threat Intelligence

CVE-2026-60167: Oracle Hospitality Simphony information disclosure in POS component

CVE-2026-60167 · Severity: high · CVSS 7.5 · Published 2026-07-21

Technologies: Oracle Simphony. Vendors: Oracle.

Executive brief

Oracle Hospitality Simphony is a point-of-sale (POS) platform used by restaurants and hotels to manage transactions and guest services. A security vulnerability in the POS component allows an unauthorized person to access the system over the network without a password. An attacker could use this to view sensitive business information or steal all data accessible to the Simphony application, potentially leading to significant data breaches and regulatory non-compliance.

Technical details

A vulnerability in the POS component of Oracle Hospitality Simphony allows an unauthenticated attacker with network access via HTTP to compromise the system. The flaw is categorized as easily exploitable and does not require user interaction. Successful exploitation results in a high confidentiality impact, allowing the attacker to gain unauthorized access to critical data or complete access to all data accessible by the Simphony application. Affected versions include 19.8 through 19.8.5, 19.9 through 19.9.3, and 19.10. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Hospitality Simphony 19.8-19.8.5, 19.9-19.9.3, 19.10

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-60167
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released

References

Related threats