Oracle Hospitality Simphony Vulnerabilities: NTLM Hash Disclosure, Arbitrary File Write, and Kiosk Authentication Bypass (CVE-2026-60167, CVE-2026-60168, CVE-2026-60169, CVE-2026-60170) — Threadlinqs Intelligence
As of 2026-07-22, Oracle Hospitality Simphony Vulnerabilities: NTLM Hash Disclosure, Arbitrary File Write, and Kiosk Authentication Bypass (CVE-2026-60167, CVE-2026-60168, CVE-2026-60169, CVE-2026-60170) is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 18 indicators of compromise.
Threat ID: TL-2026-1638 · Severity: CRITICAL · CVSS: 9.1 · Status: ACTIVE · Category: VULNERABILITY
Horizon3.ai researcher Jimi Sebree disclosed four unauthenticated, network-exploitable vulnerabilities in Oracle Hospitality Simphony POS (versions 19.8-19.8.5, 19.9-19.9.3, 19.10): a UNC path
Oracle Hospitality Simphony is a widely deployed cloud-based point-of-sale (POS) platform used across the hospitality and food-service industry to process guest transactions, manage printing/kitchen-display workflows, and support self-service ordering via the Simphony Kiosk application. On 2026-07-21, Horizon3.ai attack researcher Jimi Sebree published technical analysis of four vulnerabilities affecting Simphony versions 19.8 through 19.8.5, 19.9 through 19.9.3, and 19.10 (earlier, unsupported release lines may also be affected), coordinated with Oracle's July 2026 Critical Patch Update (cpujul2026), a mega-CPU that addressed 1,235 CVEs across 32 Oracle product families/1,449 patches in total.
CVE-2026-60167 is a UNC path coercion vulnerability in the EGateway Printing Handler. Because the handler insufficiently validates user-controlled input used to build printer/network paths, an unauthenticated network attacker can supply a crafted UNC path (e.g. pointing at an attacker-controlled SMB listener) and force the Simphony host to initiate an outbound SMB connection to it. Windows automatically attempts NTLM authentication during that outbound connection, disclosing the host's NTLM authentication material (NetNTLM hash) to the attacker. Horizon3.ai's write-up explicitly frames this as an SMB-relay-enabling primitive: the captured hash can be cracked offline to recover the plaintext service-account password, or relayed in real time (NTLM relay / SMB relay) against other hosts that accept the same credential, potentially yielding remote code execution or further lateral movement without ever needing the original password. CVSS 3.1 base score 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) — confidentiality-only impact reflecting the credential-disclosure primitive.
CVE-2026-60168 and CVE-2026-60169 are two related but independently tracked arbitrary file write vulnerabilities in the same EGateway Printing Handler, both stemming from insufficient validation of attacker-supplied paths/content before file operations are performed on the host filesystem. CVE-2026-60168 (CVSS 3.1 9.1 CRITICAL, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H) is an easily exploitable (AC:L) unauthenticated HTTP-reachable flaw enabling unauthorized creation, deletion, or modification of critical data and denial of service (host crash). CVE-2026-60169 (CVSS 3.1 8.1 HIGH, AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H) is a harder-to-exploit (AC:H) variant of the same underlying weakness class but yields complete compromise of confidentiality, integrity, and availability when successful. Chained together, an attacker can write attacker-controlled files (e.g. a web shell or scheduled task payload) to the Simphony host, establishing persistence and staging code execution — Horizon3.ai's advisory groups both file-write CVEs under 'persistent code execution preparation' as the shared impact category.
CVE-2026-60170 is an authentication bypass in the Simphony Kiosk self-service ordering application (CVSS 3.1 7.5 HIGH, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). Because the Kiosk application insufficiently validates a user-controlled input used in its authentication flow, an unauthenticated network attacker can bypass login and reach the Kiosk administrator console — a management interface not intended to be exposed to unauthenticated users. Horizon3.ai researchers demonstrated that administrator-console access can be leveraged to execute arbitrary code, establish persistence (including via unauthorized admin account creation, which Horizon3.ai flags as a specific post-exploitation indicator), access locally stored data (which may include payment/transaction artifacts depending on deployment), and pivot toward other assets on the same network segment as the kiosk terminal (common in retail/restaurant back-of-house LANs shared with POS controllers and payment infrastructure).
All four vulnerabilities are unauthenticated, network-exploitable (AV:N), require no user interaction (UI:N), require
Weaknesses (CWE)
CWE-434, CWE-287, CWE-20, CWE-73
Target sectors: hospitality, food-service, retail, point-of-sale
Target regions: Global
Detections & IOCs
As of 2026-08-15, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 18 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-60167, CVE-2026-60168, CVE-2026-60169, CVE-2026-60170, T1595.002, T1588.005, T1587.001, T1190, T1059, T1505.003, T1136.001, T1068, T1550.002, T1070.004