Unauthenticated Access Vulnerability in Oracle Hospitality OPERA 5
CVE-2026-21967
8.6HIGH
What is CVE-2026-21967?
The vulnerability in Oracle Hospitality OPERA 5 allows unauthenticated attackers with network access via HTTP to exploit the system easily. Successful exploits can lead to unauthorized access to sensitive data, enabling attackers to read, modify, or delete critical information within OPERA 5. This allows for potentially catastrophic disruptions, as attackers may also initiate partial denial of service attacks, impacting the availability of the service. Organizations using the affected versions should take immediate action to mitigate these risks.
Affected Version(s)
Oracle Hospitality OPERA 5 5.6.19.23
Oracle Hospitality OPERA 5 5.6.25.17
Oracle Hospitality OPERA 5 5.6.26.10