New at Horizon3.ai

Oracle Hospitality Simphony Multiple Vulnerabilities

Oracle’s July 2026 Critical Patch Update addresses four remotely exploitable vulnerabilities affecting Oracle Hospitality Simphony. Discovered and responsibly disclosed by Horizon3.ai researcher Jimi Sebree, the vulnerabilities affect two Simphony components: the EGateway Printing Handler and the Kiosk application. Together, they provide multiple paths for unauthenticated attackers to compromise vulnerable systems, including NTLM hash disclosure, arbitrary file writes, authentication bypass, and arbitrary code execution.

The vulnerabilities include:

  • CVE-2026-60167: UNC path coercion resulting in NTLM hash disclosure
  • CVE-2026-60168 & CVE-2026-60169: Related vulnerabilities that together enable arbitrary file writes through the EGateway Printing Handler
  • CVE-2026-60170: Authentication bypass affecting the Simphony Kiosk application that can lead to arbitrary code execution

Oracle Hospitality Simphony is widely deployed across hospitality chains, quick-service restaurants, stadiums, casinos, hotels, and other food service environments. Because these systems frequently reside on networks that process payment card data and connect to enterprise infrastructure, successful exploitation may enable lateral movement, persistence, credential compromise, or complete host compromise.

There are currently no confirmed reports of active exploitation in the wild.

Stop Guessing, Start Proving

Technical Details

Although Oracle assigned four separate CVE identifiers, the vulnerabilities fall into two functional groups affecting different Simphony components.

CVE-2026-60167: UNC Path Coercion

CVE-2026-60167 affects the EGateway Printing Handler. Improper validation of user-controlled input allows an unauthenticated attacker to supply a crafted UNC path that causes the Simphony host to initiate an outbound SMB connection to an attacker-controlled server.

Windows may automatically transmit NTLM authentication material during this connection. Captured NTLM hashes may be cracked offline or relayed to other systems, potentially facilitating credential compromise and lateral movement.

Characteristics

  • Attack vector: Network
  • Attack complexity: Low
  • Privileges required: None
  • User interaction: None
  • Primary impact: NTLM hash disclosure

CVE-2026-60168 & CVE-2026-60169: Arbitrary File Write

CVE-2026-60168 and CVE-2026-60169 affect the EGateway Printing Handler.

The vulnerabilities result from insufficient validation of attacker-controlled input before file operations are performed. Oracle assigned two CVEs to distinct weaknesses within the processing chain that together create a single arbitrary file write condition.

An unauthenticated attacker can submit crafted requests that cause arbitrary files to be written to the underlying host.

Successful exploitation may allow an attacker to:

  • Write attacker-controlled files
  • Establish persistence
  • Prepare the system for subsequent code execution
  • Facilitate additional compromise

Characteristics

  • Attack vector: Network
  • Attack complexity: Low
  • Privileges required: None
  • User interaction: None
  • Primary impact: Arbitrary file write

CVE-2026-60170: Authentication Bypass

CVE-2026-60170 affects the Simphony Kiosk application.

Improper validation of user-controlled input allows an unauthenticated attacker to bypass authentication and gain access to the Kiosk administrator console.

Horizon3.ai research demonstrated that this unauthorized administrative access can be leveraged to execute arbitrary code on the underlying host.

Successful exploitation may enable an attacker to:

  • Execute arbitrary code
  • Establish persistence
  • Access locally available data
  • Use the compromised system as a foothold for additional attacks

Characteristics

  • Attack vector: Network
  • Attack complexity: Low
  • Privileges required: None
  • User interaction: None
  • Primary impact: Authentication bypass leading to arbitrary code execution

NodeZero® Proactive Security Platform — Rapid Response

A single NodeZero Rapid Response test has been developed to safely validate whether Oracle Hospitality Simphony deployments are vulnerable to these attack paths. The tests execute real attack techniques without causing damage, giving security teams immediate clarity on whether their environment is susceptible to any of the disclosed vulnerabilities.

  • Run the Rapid Response test: Launch the Oracle Hospitality Simphony Rapid Response test from the NodeZero platform to determine whether any of the four vulnerabilities can be exploited.
  • Patch immediately: Apply Oracle’s July 2026 Critical Patch Update for your supported Simphony deployment.
  • Re-run the test: Confirm the vulnerabilities are no longer exploitable after remediation.

Affected Versions & Patch

Affected

Oracle identifies the following supported Oracle Hospitality Simphony versions as affected by these vulnerabilities:

  • 19.8 through 19.8.5
  • 19.9 through 19.9.3
  • 19.10

Earlier unsupported releases were not evaluated by Oracle and may also be vulnerable.

Fixed

Oracle addressed all four vulnerabilities in the July 2026 Critical Patch Update. Customers should obtain and install the appropriate security update for their supported Simphony deployment through My Oracle Support.

Oracle’s advisory identifies the affected release ranges but does not publish specific fixed version numbers.

Mitigations

Until patching is complete:

  • Restrict access to the EGateway Printing Handler and Kiosk administrative interfaces to trusted systems and network segments.
  • Prevent direct internet access to Simphony administrative services.
  • Restrict or block outbound SMB (TCP 445) from Simphony hosts wherever operationally feasible.
  • Require SMB signing and Extended Protection for Authentication where supported to reduce NTLM relay attacks.
  • Monitor Simphony hosts for unexpected outbound SMB connections.
  • Monitor application and system directories for unauthorized file creation or modification.
  • Review Kiosk hosts for unauthorized administrator accounts, unexpected processes, configuration changes, or persistence mechanisms.
  • Segment Simphony hosts from payment processing systems, Active Directory, and other critical enterprise infrastructure wherever possible.

These measures may reduce exposure but do not eliminate the underlying vulnerabilities.

Timeline

  • July 21, 2026: Oracle released the July 2026 Critical Patch Update, disclosing CVE-2026-60167, CVE-2026-60168, CVE-2026-60169, and CVE-2026-60170 and publishing fixes for supported Oracle Hospitality Simphony deployments.
  • July 21, 2026: Horizon3.ai released a NodeZero Rapid Response test enabling customers to validate exposure and verify remediation.

References

Read about other CVEs

NodeZero® Platform

Implement a continuous find, fix, and verify loop with NodeZero

The NodeZero® platform empowers your organization to reduce your security risks by autonomously finding exploitable weaknesses in your network, giving you detailed guidance around how to priortize and fix them, and having you immediately verify that your fixes are effective.
Explore NodeZero

Recognized By