What is CVE-2026-60591?
CVE-2026-60591 is a vulnerability in the POS component of Oracle Hospitality Simphony, affecting versions 19.8-19.8.5, 19.9-19.9.3, and 19.10-19.10.1. Exploitation is possible via HTTP network access without authentication, requiring immediate patching of affected systems.
Azərbaycanca: CVE-2026-60591, Oracle Hospitality Simphony POS komponentində aşkarlanmış boşluqdur. 19.8-19.8.5, 19.9-19.9.3 və 19.10-19.10.1 versiyalarına təsir edir. İstismar şəbəkə üzərindən HTTP ilə autentifikasiya olmadan mümkündür, təsirə məruz qalan sistemlər dərhal yenilənməlidir.
Related CVEs
link basis: shared vendor: Oracle
FAQ2
Which versions of Oracle Hospitality Simphony are affected by CVE-2026-60591?
The vulnerability affects the POS component of Oracle Hospitality Simphony versions 19.8 through 19.8.5, 19.9 through 19.9.3, and 19.10 through 19.10.1.
Is authentication required to exploit CVE-2026-60591?
No, the vulnerability can be exploited over the network via HTTP without any authentication.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.