Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cpujan2026.html |
|
Sat, 18 Apr 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated Authorization Bypass in Oracle Hospitality OPERA 5 Property Services | |
| Weaknesses | CWE-285 |
Thu, 29 Jan 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oracle hospitality Opera 5
|
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:oracle:hospitality_opera_5:5.6.19.23:*:*:*:*:*:*:* cpe:2.3:a:oracle:hospitality_opera_5:5.6.25.17:*:*:*:*:*:*:* cpe:2.3:a:oracle:hospitality_opera_5:5.6.26.10:*:*:*:*:*:*:* cpe:2.3:a:oracle:hospitality_opera_5:5.6.27.4:*:*:*:*:*:*:* |
|
| Vendors & Products |
Oracle hospitality Opera 5
|
Wed, 21 Jan 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 20 Jan 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera). Supported versions that are affected are 5.6.19.23, 5.6.25.17, 5.6.26.10 and 5.6.27.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5 Property Services. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hospitality OPERA 5 Property Services, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality OPERA 5 Property Services accessible data as well as unauthorized read access to a subset of Oracle Hospitality OPERA 5 Property Services accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). | |
| First Time appeared |
Oracle
Oracle hospitality Opera 5 Property Services |
|
| CPEs | cpe:2.3:a:oracle:hospitality_opera_5_property_services:5.6.19.23:*:*:*:*:*:*:* cpe:2.3:a:oracle:hospitality_opera_5_property_services:5.6.25.17:*:*:*:*:*:*:* cpe:2.3:a:oracle:hospitality_opera_5_property_services:5.6.26.10:*:*:*:*:*:*:* cpe:2.3:a:oracle:hospitality_opera_5_property_services:5.6.27.4:*:*:*:*:*:*:* |
|
| Vendors & Products |
Oracle
Oracle hospitality Opera 5 Property Services |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published:
Updated: 2026-01-21T19:54:47.033Z
Reserved: 2026-01-05T18:07:34.714Z
Link: CVE-2026-21966
Updated: 2026-01-21T19:54:35.863Z
Status : Analyzed
Published: 2026-01-20T22:15:59.607
Modified: 2026-01-29T14:48:47.800
Link: CVE-2026-21966
No data.
OpenCVE Enrichment
Updated: 2026-04-18T04:30:35Z