Threat reportVulnerabilityTL-2026-1638
Oracle Hospitality Simphony Vulnerabilities: NTLM Hash Disclosure, Arbitrary File Write, and Kiosk Authentication Bypass (CVE-2026-60167, CVE-2026-60168, CVE-2026-60169, CVE-2026-60170)
Oracle Hospitality Simphony Vulnerabilities (TL-2026-1638) is a critical-severity software vulnerability scored CVSS 9.1, first published 2026-07-22. It has no confirmed attribution, affects Oracle Oracle Hospitality Simphony, references 4 CVEs (CVE-2026-60167, CVE-2026-60168, CVE-2026-60169), maps to 19 MITRE ATT&CK techniques (T1005, T1046, T1059), and is covered by 9 detection rules and 18 indicators of compromise.
- CVSS
- 9.1/10Critical
- CVEs
- 4Referenced vulnerabilities
- Techniques
- 19MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 18Indicators of compromise
Key facts for TL-2026-1638
- Threat ID
- TL-2026-1638
- Severity
- CRITICAL
- CVSS
- 9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- hospitality, food-service, retail, point-of-sale
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 18
Malware and tooling in Oracle Hospitality Simphony Vulnerabilities
Malware and tooling: NodeZero Rapid Response
How Oracle Hospitality Simphony Vulnerabilities works
Horizon3.ai researcher Jimi Sebree disclosed four unauthenticated, network-exploitable vulnerabilities in Oracle Hospitality Simphony POS (versions 19.8-19.8.5, 19.9-19.9.3, 19.10): a UNC path coercion flaw in the EGateway Printing Handler that discloses NTLM authentication material (CVE-2026-60167, CVSS 7.5), two arbitrary file write issues in the same component (CVE-2026-60168, CVSS 9.1 CRITICAL; CVE-2026-60169, CVSS 8.1), and an authentication bypass in the Simphony Kiosk application that grants access to the Kiosk administrator console and was demonstrated to enable arbitrary code execution (CVE-2026-60170, CVSS 7.5). Oracle shipped fixes in the July 2026 Critical Patch Update; Horizon3.ai simultaneously released a NodeZero Rapid Response module. Not present in CISA KEV; no active in-the-wild exploitation confirmed as of disclosure.
Oracle Hospitality Simphony is a widely deployed cloud-based point-of-sale (POS) platform used across the hospitality and food-service industry to process guest transactions, manage printing/kitchen-display workflows, and support self-service ordering via the Simphony Kiosk application. On 2026-07-21, Horizon3.ai attack researcher Jimi Sebree published technical analysis of four vulnerabilities affecting Simphony versions 19.8 through 19.8.5, 19.9 through 19.9.3, and 19.10 (earlier, unsupported release lines may also be affected), coordinated with Oracle's July 2026 Critical Patch Update (cpujul2026), a mega-CPU that addressed 1,235 CVEs across 32 Oracle product families/1,449 patches in total.
CVE-2026-60167 is a UNC path coercion vulnerability in the EGateway Printing Handler. Because the handler insufficiently validates user-controlled input used to build printer/network paths, an unauthenticated network attacker can supply a crafted UNC path (e.g. pointing at an attacker-controlled SMB listener) and force the Simphony host to initiate an outbound SMB connection to it. Windows automatically attempts NTLM authentication during that outbound connection, disclosing the host's NTLM authentication material (NetNTLM hash) to the attacker. Horizon3.ai's write-up explicitly frames this as an SMB-relay-enabling primitive: the captured hash can be cracked offline to recover the plaintext service-account password, or relayed in real time (NTLM relay / SMB relay) against other hosts that accept the same credential, potentially yielding remote code execution or further lateral movement without ever needing the original password. CVSS 3.1 base score 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) — confidentiality-only impact reflecting the credential-disclosure primitive.
CVE-2026-60168 and CVE-2026-60169 are two related but independently tracked arbitrary file write vulnerabilities in the same EGateway Printing Handler, both stemming from insufficient validation of attacker-supplied paths/content before file operations are performed on the host filesystem. CVE-2026-60168 (CVSS 3.1 9.1 CRITICAL, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H) is an easily exploitable (AC:L) unauthenticated HTTP-reachable flaw enabling unauthorized creation, deletion, or modification of critical data and denial of service (host crash). CVE-2026-60169 (CVSS 3.1 8.1 HIGH, AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H) is a harder-to-exploit (AC:H) variant of the same underlying weakness class but yields complete compromise of confidentiality, integrity, and availability when successful. Chained together, an attacker can write attacker-controlled files (e.g. a web shell or scheduled task payload) to the Simphony host, establishing persistence and staging code execution — Horizon3.ai's advisory groups both file-write CVEs under 'persistent code execution preparation' as the shared impact category.
CVE-2026-60170 is an authentication bypass in the Simphony Kiosk self-service ordering application (CVSS 3.1 7.5 HIGH, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). Because the Kiosk application insufficiently validates a user-controlled input used in its authentication flow, an unauthenticated network attacker can bypass login and reach the Kiosk administrator console — a management interface not intended to be exposed to unauthenticated users. Horizon3.ai researchers demonstrated that administrator-console access can be leveraged to execute arbitrary code, establish persistence (including via unauthorized admin account creation, which Horizon3.ai flags as a specific post-exploitation indicator), access locally stored data (which may include payment/transaction artifacts depending on deployment), and pivot toward other assets on the same network segment as the kiosk terminal (common in retail/restaurant back-of-house LANs shared with POS controllers and payment infrastructure).
All four vulnerabilities are unauthenticated, network-exploitable (AV:N), require no user interaction (UI:N), require no privileges (PR:N), and were disclosed with coordinated Oracle patches in the July 2026 CPU. Horizon3.ai's public technical write-up withheld a full weaponized proof-of-concept but described attack mechanics in sufficient detail (UNC coercion pattern, file-write primitive, kiosk auth-bypass class, HTTP-endpoint reachability) that a motivated attacker could plausibly reconstruct working exploits, particularly given Simphony's prevalence in hospitality environments where POS/kiosk terminals are frequently internet- or vendor-network-adjacent. Horizon3.ai's mitigation guidance explicitly recommends Extended Protection for Authentication (EPA) alongside SMB signing, and monitoring for unauthorized SMB connections, unexpected file modifications, and unauthorized admin account creation. As of 2026-07-22 the four CVEs are not present in the CISA Known Exploited Vulnerabilities catalog (1,653 entries as of that date), consistent with the 'no active exploitation confirmed' assessment; Horizon3.ai released a single NodeZero Rapid Response test module allowing customers to both validate exploitability pre-patch and verify remediation post-patch without causing system damage.
MITRE ATT&CK techniques used in TL-2026-1638
Collection
Discovery
T1046 Network Service Discovery
Execution
T1059 Command and Scripting Interpreter
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Defense Evasion
Command and Control
T1071 Application Layer Protocol
Credential Access
T1110.002 Password Cracking; T1187 Forced Authentication; T1557.001 Name Resolution Poisoning and SMB Relay
Persistence
T1136.001 Local Account; T1505.003 Web Shell
Initial Access
T1190 Exploit Public-Facing Application
Lateral Movement
T1210 Exploitation of Remote Services
Impact
T1485 Data Destruction; T1499 Endpoint Denial of Service
lateral-movement
Resource Development
T1587.001 Malware; T1588.005 Exploits
Reconnaissance
Affected products and versions in Oracle Hospitality Simphony Vulnerabilities
- Oracle — Oracle Hospitality Simphony
Vulnerable versions: 19.8; 19.8.1; 19.8.2; 19.8.3; 19.8.4; 19.8.5; 19.9; 19.9.1; 19.9.2; 19.9.3
Fixed in: Patched via Oracle Critical Patch Update - July 2026 (cpujul2026)
Remediation for Oracle Hospitality Simphony Vulnerabilities
Patches
- Oracle Critical Patch Update - July 2026 (cpujul2026)
Immediate actions
- Apply Oracle's July 2026 Critical Patch Update to all Oracle Hospitality Simphony deployments running 19.8-19.8.5, 19.9-19.9.3, or 19.10
- Restrict network access to the EGateway Printing Handler and Kiosk administrator console to trusted management networks only
- Enforce SMB signing and Extended Protection for Authentication (EPA); block outbound SMB (TCP 445, 137-139) from Simphony hosts to the internet to prevent NTLM hash disclosure via coerced authentication
- Disable or restrict NTLM authentication in favor of Kerberos where operationally feasible on Simphony hosts
Workarounds
- If immediate patching is not possible, block inbound access to the EGateway Printing Handler and Kiosk admin console from untrusted networks
- Enable SMB signing enforcement to mitigate NTLM relay even if hash disclosure occurs
- Monitor for unexpected outbound SMB connection attempts and unauthorized admin account creation originating from Simphony hosts
Longer-term hardening
- Segment POS/kiosk terminals onto isolated VLANs separate from payment processing and corporate infrastructure
- Deploy EDR/host monitoring on Simphony EGateway and Kiosk hosts to detect anomalous outbound SMB connections, unexpected file writes, and unauthorized admin account creation
- Rotate credentials for any service accounts used by the EGateway Printing Handler following patch deployment
- Implement egress filtering to block unsolicited outbound SMB from POS network segments
- Run Horizon3.ai NodeZero Rapid Response (or equivalent authorized testing) post-patch to verify remediation effectiveness
CVEs associated with Oracle Hospitality Simphony Vulnerabilities
CVE-2026-60167, CVE-2026-60168, CVE-2026-60169, CVE-2026-60170
Weaknesses (CWE) in Oracle Hospitality Simphony Vulnerabilities
Timeline of Oracle Hospitality Simphony Vulnerabilities
- NVD published individual CVE records for CVE-2026-60167 through CVE-2026-60170, each referencing Oracle's cpujul2026 advisory as the sole reference source.
- Horizon3.ai's advisory recommended interim mitigations including SMB signing enforcement, Extended Protection for Authentication (EPA), network segmentation, blocking direct internet exposure of admin interfaces, and monitoring for suspicious outbound SMB connections, unexpected file modifications, and unauthorized admin account creation on Simphony hosts.
- Horizon3.ai released a single NodeZero Rapid Response test module enabling customers to check exploitability of the disclosed Simphony vulnerabilities pre-patch and verify remediation post-patch without causing system damage.
- Oracle published CVSS 3.1 base scores for the four CVEs: 7.5 (CVE-2026-60167), 9.1 CRITICAL (CVE-2026-60168), 8.1 (CVE-2026-60169), and 7.5 (CVE-2026-60170), all AV:N/AC:L-or-H/PR:N/UI:N.
- Oracle released fixes for all four Simphony vulnerabilities as part of the July 2026 Critical Patch Update (cpujul2026), a mega-CPU addressing 1,235 CVEs across 32 product families / 1,449 patches total.
- Horizon3.ai researcher Jimi Sebree publicly disclosed technical details of CVE-2026-60167, CVE-2026-60168, CVE-2026-60169, and CVE-2026-60170 affecting Oracle Hospitality Simphony 19.8-19.8.5, 19.9-19.9.3, and 19.10.
- Report ingested into TL-Intel-Harness RSS backlog from the Horizon3.ai Attack Research feed for hunt/research triage.
- Verification against the CISA Known Exploited Vulnerabilities catalog (1,653 entries as of 2026-07-22) confirmed none of the four Simphony CVEs are listed, corroborating the 'no active exploitation confirmed' assessment at time of research.
Sources cited for Oracle Hospitality Simphony Vulnerabilities
- Oracle Hospitality Simphony Vulnerabilities
- Oracle Critical Patch Update Advisory - July 2026
- Text Form of Oracle CPU July 2026 Risk Matrices
- NVD - CVE-2026-60167
- NVD - CVE-2026-60168
- NVD - CVE-2026-60169
- NVD - CVE-2026-60170
- Horizon3.ai NodeZero Rapid Response
- Rapid Response - HORIZON3 Documentation
- CISA Known Exploited Vulnerabilities Catalog
- Oracle July 2026 Critical Patch Update Addresses 1235 CVEs - Threat Radar
- Map of CVE to Advisory/Alert - Oracle
Detection coverage for TL-2026-1638
As of 2026-07-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1638 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.