


Perceptive Security
SOC/SIEM Consultancy

Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera). Supported versions that are af…
Published:
27 May 2026 at 22:00:00
Alert date:
28 May 2026 at 22:04:22
Source:
nvd.nist.gov
Enterprise Applications
Critical vulnerability in Oracle Hospitality OPERA 5 Property Services affecting multiple versions (5.6.19.24, 5.6.22, 5.6.25.19, 5.6.27.6, 5.6.28). The vulnerability allows unauthenticated attackers with network access via HTTP to completely compromise the system. Exploitation is easy and can result in full takeover of Oracle Hospitality OPERA 5 Property Services. CVSS 3.1 Base Score is 9.8 indicating critical severity with high impact on confidentiality, integrity, and availability. The vulnerability requires no authentication and no user interaction, making it particularly dangerous for hospitality industry systems.
Technical details
Mitigation steps:
Affected products:
Oracle Hospitality OPERA 5 Property Services
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-34311
https://www.oracle.com/security-alerts/cspumay2026.html
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
