Unauthenticated Access Vulnerability in Oracle Hospitality Simphony
CVE-2026-60590

7.5HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-60590?

An exploit in the Oracle Hospitality Simphony product allows unauthenticated attackers with network access via HTTP to compromise the entire system. This vulnerability poses a significant risk, enabling attackers to gain unauthorized access to confidential data or even complete access to all data accessible through Oracle Hospitality Simphony. Supported versions including 19.8-19.8.5, 19.9-19.9.3, and 19.10-19.10.1 are particularly vulnerable, highlighting the urgency for users to update and secure their systems against potential exploits.

Affected Version(s)

Oracle Hospitality Simphony 19.8 <= 19.8.5

Oracle Hospitality Simphony 19.9 <= 19.9.3

Oracle Hospitality Simphony 19.10 <= 19.10.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.