CVE-2026-60168: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hospitality Simphony accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hospitality Simphony. in Oracle Corporation Oracle Hospitality Simphon
CVE-2026-60168 is a critical vulnerability in Oracle Hospitality Simphony versions 19.8 through 19.10. It allows an unauthenticated attacker with network access via HTTP to compromise the system. Exploitation can lead to unauthorized creation, deletion, or modification of critical data and can cause a hang or repeated crashes, resulting in a denial of service. The vulnerability has a CVSS 3.1 base score of 9.1, indicating high severity with significant integrity and availability impacts. No official patch or remediation level has been explicitly stated in the vendor advisory as of the publication date.
AI Analysis
Technical Summary
This vulnerability affects Oracle Hospitality Simphony, specifically versions 19.8, 19.9, and 19.10. It is an easily exploitable flaw that requires no authentication and can be triggered remotely over HTTP. Successful exploitation grants an attacker unauthorized ability to create, delete, or modify critical data within the system, as well as cause the application to hang or crash repeatedly, resulting in a complete denial of service. The CVSS vector indicates no privileges or user interaction are required, with network attack vector and low attack complexity. The vulnerability is categorized under CWE-284 (Improper Access Control). The vendor advisory references a Critical Patch Update released in July 2026 but does not explicitly confirm a patch for this specific vulnerability within the advisory content provided.
Potential Impact
An attacker can remotely exploit this vulnerability without authentication to gain unauthorized access to modify critical data in Oracle Hospitality Simphony or cause a denial of service by hanging or crashing the application. This compromises data integrity and system availability, potentially disrupting business operations dependent on the affected software.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory at https://www.oracle.com/security-alerts/cpujul2026.html for current remediation guidance. Oracle recommends applying Critical Patch Updates promptly to address vulnerabilities. Until a patch is confirmed and applied, restrict network access to Oracle Hospitality Simphony HTTP interfaces to trusted sources only to reduce exposure.
CVE-2026-60168: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hospitality Simphony accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hospitality Simphony. in Oracle Corporation Oracle Hospitality Simphon
Description
CVE-2026-60168 is a critical vulnerability in Oracle Hospitality Simphony versions 19.8 through 19.10. It allows an unauthenticated attacker with network access via HTTP to compromise the system. Exploitation can lead to unauthorized creation, deletion, or modification of critical data and can cause a hang or repeated crashes, resulting in a denial of service. The vulnerability has a CVSS 3.1 base score of 9.1, indicating high severity with significant integrity and availability impacts. No official patch or remediation level has been explicitly stated in the vendor advisory as of the publication date.
CVSS v3.1
Score 9.1critical
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability affects Oracle Hospitality Simphony, specifically versions 19.8, 19.9, and 19.10. It is an easily exploitable flaw that requires no authentication and can be triggered remotely over HTTP. Successful exploitation grants an attacker unauthorized ability to create, delete, or modify critical data within the system, as well as cause the application to hang or crash repeatedly, resulting in a complete denial of service. The CVSS vector indicates no privileges or user interaction are required, with network attack vector and low attack complexity. The vulnerability is categorized under CWE-284 (Improper Access Control). The vendor advisory references a Critical Patch Update released in July 2026 but does not explicitly confirm a patch for this specific vulnerability within the advisory content provided.
Potential Impact
An attacker can remotely exploit this vulnerability without authentication to gain unauthorized access to modify critical data in Oracle Hospitality Simphony or cause a denial of service by hanging or crashing the application. This compromises data integrity and system availability, potentially disrupting business operations dependent on the affected software.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory at https://www.oracle.com/security-alerts/cpujul2026.html for current remediation guidance. Oracle recommends applying Critical Patch Updates promptly to address vulnerabilities. Until a patch is confirmed and applied, restrict network access to Oracle Hospitality Simphony HTTP interfaces to trusted sources only to reduce exposure.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- oracle
- Date Reserved
- 2026-07-08T15:51:40.516Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://www.oracle.com/security-alerts/cpujul2026.html","vendor":"Oracle"}]
Threat ID: 6a5fe6d49c2644c7f8cb0d29
Added to database: 07/21/2026, 21:38:28 UTC
Last enriched: 07/30/2026, 05:03:52 UTC
Last updated: 07/31/2026, 19:22:59 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.