What is CVE-2026-21954?
This vulnerability affects Oracle Retail Xstore Point of Service (version 21.0.3) in the Xstore Mobile component. It allows a low-privileged attacker with network access via HTTP to easily compromise the system. Immediate patching as per Oracle's security advisory is required.
Azərbaycanca: Bu boşluq Oracle Retail Xstore Point of Service (versiya 21.0.3) məhsulunun Xstore Mobile komponentində aşkarlanıb. Şəbəkə üzərindən HTTP ilə aşağı səlahiyyətli autentifikasiya olunmuş hücumçuya sistemi ələ keçirməyə imkan verir. Dərhal Oracle-ın təqdim etdiyi təhlükəsizlik yaması tətbiq edilməlidir.
Related CVEs
link basis: shared vendor: Oracle
FAQ2
In which component of Oracle Retail Xstore Point of Service was CVE-2026-21954 discovered?
It was discovered in the Xstore Mobile component.
What level of privilege does an attacker need to exploit CVE-2026-21954?
A low-privileged authenticated attacker is required.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.