Executive brief
Oracle Hospitality Simphony, a point-of-sale (POS) platform used by restaurants and hotels, contains a critical vulnerability. An unauthenticated attacker can remotely exploit this flaw over the network to delete or modify business-critical data and shut down the system. This could lead to significant operational downtime and the loss of transaction or configuration records.
Technical details
A vulnerability in the POS component of Oracle Hospitality Simphony allows an unauthenticated attacker with network access via HTTP to compromise the system. The flaw is categorized as easily exploitable and does not require user interaction. Successful exploitation can result in unauthorized creation, deletion, or modification of all accessible data within the application. Additionally, attackers can cause a hang or a frequently repeatable crash, leading to a complete denial of service (DoS). The vulnerability affects versions 19.8-19.8.5, 19.9-19.9.3, and 19.10.
Affected products
- Oracle Hospitality Simphony 19.8-19.8.5, 19.9-19.9.3, 19.10
Timeline
- 2026-07-21: advisory: Published as part of the Oracle Critical Patch Update (CPU) July 2026