Junglewise Threat Intelligence

CVE-2026-60170: Oracle Hospitality Simphony information disclosure in POS component

CVE-2026-60170 · Severity: high · CVSS 7.5 · Published 2026-07-21

Vendors: Oracle.

Executive brief

Oracle Hospitality Simphony, a point-of-sale (POS) platform used extensively in the food and beverage industry, contains a security vulnerability in its POS component. An unauthenticated attacker can exploit this over the network to gain unauthorized access to sensitive business data. This could lead to the exposure of critical information stored within the hospitality management system, potentially impacting customer privacy and operational integrity.

Technical details

A vulnerability in the POS component of Oracle Hospitality Simphony allows an unauthenticated attacker with network access via HTTP to compromise the system. The exploit is characterized as 'easily exploitable' and does not require user interaction or elevated privileges. Successful exploitation results in a high confidentiality impact, allowing the attacker to access all data accessible to the Simphony application. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Hospitality Simphony 19.8-19.8.5, 19.9-19.9.3, 19.10

Timeline

  • 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this advisory.
  • 2026-07-21: disclosed: CVE-2026-60170 was published to the NVD.

References