Oracle’s July 2026 Critical Patch Update addresses four remotely exploitable vulnerabilities affecting Oracle Hospitality Simphony. Discovered and responsibly disclosed by Horizon3.ai researcher Jimi Sebree, the vulnerabilities affect two Simphony components: the EGateway Printing Handler and the Kiosk application. Together, they provide multiple paths for unauthenticated attackers to compromise vulnerable systems, including NTLM hash disclosure, arbitrary file writes, authentication bypass, and arbitrary code execution.
The vulnerabilities include:
Oracle Hospitality Simphony is widely deployed across hospitality chains, quick-service restaurants, stadiums, casinos, hotels, and other food service environments. Because these systems frequently reside on networks that process payment card data and connect to enterprise infrastructure, successful exploitation may enable lateral movement, persistence, credential compromise, or complete host compromise.
There are currently no confirmed reports of active exploitation in the wild.
Although Oracle assigned four separate CVE identifiers, the vulnerabilities fall into two functional groups affecting different Simphony components.
CVE-2026-60167 affects the EGateway Printing Handler. Improper validation of user-controlled input allows an unauthenticated attacker to supply a crafted UNC path that causes the Simphony host to initiate an outbound SMB connection to an attacker-controlled server.
Windows may automatically transmit NTLM authentication material during this connection. Captured NTLM hashes may be cracked offline or relayed to other systems, potentially facilitating credential compromise and lateral movement.
Characteristics
CVE-2026-60168 and CVE-2026-60169 affect the EGateway Printing Handler.
The vulnerabilities result from insufficient validation of attacker-controlled input before file operations are performed. Oracle assigned two CVEs to distinct weaknesses within the processing chain that together create a single arbitrary file write condition.
An unauthenticated attacker can submit crafted requests that cause arbitrary files to be written to the underlying host.
Successful exploitation may allow an attacker to:
Characteristics
CVE-2026-60170 affects the Simphony Kiosk application.
Improper validation of user-controlled input allows an unauthenticated attacker to bypass authentication and gain access to the Kiosk administrator console.
Horizon3.ai research demonstrated that this unauthorized administrative access can be leveraged to execute arbitrary code on the underlying host.
Successful exploitation may enable an attacker to:
Characteristics
A single NodeZero Rapid Response test has been developed to safely validate whether Oracle Hospitality Simphony deployments are vulnerable to these attack paths. The tests execute real attack techniques without causing damage, giving security teams immediate clarity on whether their environment is susceptible to any of the disclosed vulnerabilities.
Oracle identifies the following supported Oracle Hospitality Simphony versions as affected by these vulnerabilities:
Earlier unsupported releases were not evaluated by Oracle and may also be vulnerable.
Oracle addressed all four vulnerabilities in the July 2026 Critical Patch Update. Customers should obtain and install the appropriate security update for their supported Simphony deployment through My Oracle Support.
Oracle’s advisory identifies the affected release ranges but does not publish specific fixed version numbers.
Until patching is complete:
These measures may reduce exposure but do not eliminate the underlying vulnerabilities.