SYS::ONLINE
Wasteland.
Briefs1404
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60168 2026-07-21

CVE-2026-60168: Critical Unauthenticated Flaw in Oracle Hospitality Simphony POS

"A critical, easily exploitable vulnerability in Oracle Hospitality Simphony lets unauthenticated network attackers tamper with or destroy point-of-sale data and crash the system entirely."

A critical, easily exploitable vulnerability in Oracle Hospitality Simphony lets unauthenticated network attackers tamper with or destroy point-of-sale data and crash the system entirely.

What Is It

CVE-2026-60168 is a critical vulnerability in the POS component of Oracle Hospitality Simphony, part of Oracle Food and Beverage Applications. Per the NVD record, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via HTTP to compromise the product. There are no prerequisites: the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H) confirms network attack vector, low complexity, no privileges, and no user interaction required. It carries a CVSS 3.1 Base Score of 9.1 (CRITICAL), driven by high integrity and availability impacts.

Why It Matters

Successful exploitation can result in unauthorized creation, deletion, or modification of critical data; up to all data accessible to Oracle Hospitality Simphony. Attackers can also cause a hang or a frequently repeatable crash, amounting to a complete denial of service (DOS). Because no authentication is needed and the attack is delivered over HTTP, exposed instances face a low bar for compromise. Note that confidentiality impact is rated NONE; the risk centers on data integrity and system availability rather than data disclosure.

What's Vulnerable

Affected Oracle Hospitality Simphony versions, per Oracle and the NVD record, are:

Patch Status

The CVE was published on 2026-07-21 with a vulnerability status of "Received." The source identifier is Oracle ([email protected]), and the sole reference is Oracle's Critical Patch Update advisory for July 2026, where remediation is addressed. Administrators running the affected versions should consult that advisory and apply the corresponding fixes. The supplied source material contains no CISA KEV entry, so there is no confirmation of active exploitation at this time.

Sources