Executive brief
Oracle Hospitality OPERA 5 Property Services is a property management system used by hospitality organizations to manage guest operations, bookings, and services. An unauthenticated attacker can exploit a vulnerability in the Opera Servlet component via HTTP requests to gain complete control of the system, though successful exploitation requires social engineering or user interaction. This could lead to unauthorized access to guest data, operational disruption, and full compromise of hotel operations.
Technical details
The vulnerability is an easily exploitable weakness in the Opera Servlet component of Oracle Hospitality OPERA 5 Property Services versions 5.6.28.0 through 5.6.28.1. The vulnerability allows unauthenticated network-based exploitation via HTTP, but requires user interaction from a third party (not the attacker) to be successfully exploited. Successful attacks result in complete takeover of the application, with impact on confidentiality, integrity, and availability. The exact root cause and vulnerable code path are not disclosed in the advisory, but the requirement for user interaction and network-only attack vector suggest either a phishing/social engineering vector or a client-side code injection (XSS/CSRF) vulnerability.
Affected products
- Oracle Hospitality OPERA 5 Property Services 5.6.28.0 to 5.6.28.1
Timeline
- 2026-08-18: disclosed