Authentication Bypass in Oracle Hospitality Simphony by Oracle
CVE-2026-60169
8.1HIGH
What is CVE-2026-60169?
A vulnerability exists in Oracle Hospitality Simphony, part of Oracle's Food and Beverage Applications, which could allow an unauthenticated attacker to exploit the system via HTTP. The affected versions (19.8-19.8.5, 19.9-19.9.3, and 19.10) are susceptible to unauthorized access, posing significant risks including the potential for system takeover and compromising confidentiality, integrity, and availability.
Affected Version(s)
Oracle Hospitality Simphony 19.8 <= 19.8.5
Oracle Hospitality Simphony 19.9 <= 19.9.3
Oracle Hospitality Simphony 19.10