Exploit Vulnerability in Oracle Hospitality OPERA Product by Oracle
CVE-2026-21966
6.1MEDIUM
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 20 January 2026
What is CVE-2026-21966?
A security flaw exists in Oracle Hospitality OPERA 5 Property Services, allowing unauthenticated network access via HTTP, potentially enabling attackers to manipulate sensitive data. While direct exploitation may require human interaction, the implications could extend significantly to other associated products. Successful exploitation could result in unauthorized modifications or retrieval of data, posing a serious risk to data integrity and confidentiality.
Affected Version(s)
Oracle Hospitality OPERA 5 Property Services 5.6.19.23
Oracle Hospitality OPERA 5 Property Services 5.6.25.17
Oracle Hospitality OPERA 5 Property Services 5.6.26.10