Exploit Vulnerability in Oracle Hospitality OPERA Product by Oracle
CVE-2026-21966

6.1MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
20 January 2026

What is CVE-2026-21966?

A security flaw exists in Oracle Hospitality OPERA 5 Property Services, allowing unauthenticated network access via HTTP, potentially enabling attackers to manipulate sensitive data. While direct exploitation may require human interaction, the implications could extend significantly to other associated products. Successful exploitation could result in unauthorized modifications or retrieval of data, posing a serious risk to data integrity and confidentiality.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Oracle Hospitality OPERA 5 Property Services 5.6.19.23

Oracle Hospitality OPERA 5 Property Services 5.6.25.17

Oracle Hospitality OPERA 5 Property Services 5.6.26.10

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.