Junglewise Threat Intelligence

CVE-2026-60169: Oracle Hospitality Simphony compromise in POS component

CVE-2026-60169 · Severity: high · CVSS 8.1 · Published 2026-07-21

Technologies: Oracle Simphony. Vendors: Oracle.

Executive brief

Oracle Hospitality Simphony is a point-of-sale (POS) platform used by restaurants and hotels to manage transactions and operations. A security vulnerability in this system could allow an unauthorized person to gain full control over the POS environment via the network. This could lead to significant business disruptions, loss of sensitive customer data, and unauthorized access to financial transaction records.

Technical details

A vulnerability exists in the POS component of Oracle Hospitality Simphony versions 19.8 through 19.10. The flaw allows an unauthenticated attacker with network access via HTTP to compromise the application. While the attack complexity is rated as high, a successful exploit can result in a complete takeover of the affected Simphony instance, impacting confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Hospitality Simphony 19.8-19.8.5, 19.9-19.9.3, 19.10

Timeline

  • 2026-07-21: advisory: Initial disclosure by Oracle and NVD publication.

References

Related threats