Junglewise Threat Intelligence

CVE-2026-71106: Oracle Hospitality OPERA 5 Property Services HTTP request handling vulnerability

CVE-2026-71106 · Severity: high · CVSS 8.8 · Published 2026-08-18

Vendors: Oracle.

Executive brief

Oracle Hospitality OPERA 5 Property Services is a property management system used by hospitality organizations to manage guest operations, bookings, and services. An unauthenticated attacker can exploit a vulnerability in the Opera Servlet component via HTTP requests to gain complete control of the system, though successful exploitation requires social engineering or user interaction. This could lead to unauthorized access to guest data, operational disruption, and full compromise of hotel operations.

Technical details

The vulnerability is an easily exploitable weakness in the Opera Servlet component of Oracle Hospitality OPERA 5 Property Services versions 5.6.28.0 through 5.6.28.1. The vulnerability allows unauthenticated network-based exploitation via HTTP, but requires user interaction from a third party (not the attacker) to be successfully exploited. Successful attacks result in complete takeover of the application, with impact on confidentiality, integrity, and availability. The exact root cause and vulnerable code path are not disclosed in the advisory, but the requirement for user interaction and network-only attack vector suggest either a phishing/social engineering vector or a client-side code injection (XSS/CSRF) vulnerability.

Affected products

  • Oracle Hospitality OPERA 5 Property Services 5.6.28.0 to 5.6.28.1

Timeline

  • 2026-08-18: disclosed

References

Related threats