Network-Based Vulnerability in Oracle Hospitality Simphony by Oracle
CVE-2026-60591

9.1CRITICAL

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-60591?

A vulnerability in Oracle Hospitality Simphony allows unauthenticated attackers with network access via HTTP to exploit the system. The affected versions, including 19.8-19.8.5, 19.9-19.9.3, and 19.10-19.10.1, can be compromised, leading to unauthorized creation, modification, or deletion of critical data. Additionally, successful exploitation may result in a complete denial of service (DoS), causing the system to hang or frequently crash, thus severely impacting the availability of services.

Affected Version(s)

Oracle Hospitality Simphony 19.8 <= 19.8.5

Oracle Hospitality Simphony 19.9 <= 19.9.3

Oracle Hospitality Simphony 19.10 <= 19.10.1

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.