# Oracle Hospitality Simphony Vulnerabilities: NTLM Hash Disclosure, Arbitrary File Write, and Kiosk Authentication Bypass (CVE-2026-60167, CVE-2026-60168, CVE-2026-60169, CVE-2026-60170)

> Horizon3.ai researcher Jimi Sebree disclosed four unauthenticated, network-exploitable vulnerabilities in Oracle Hospitality Simphony POS (versions 19.8-19.8.5, 19.9-19.9.3, 19.10): a UNC path coercion flaw in the EGateway Printing Handler that discloses NTLM authentication material (CVE-2026-60167, CVSS 7.5), two arbitrary file write issues in the same component (CVE-2026-60168, CVSS 9.1 CRITICAL; CVE-2026-60169, CVSS 8.1), and an authentication bypass in the Simphony Kiosk application that grants access to the Kiosk administrator console and was demonstrated to enable arbitrary code execution (CVE-2026-60170, CVSS 7.5). Oracle shipped fixes in the July 2026 Critical Patch Update; Horizon3.ai simultaneously released a NodeZero Rapid Response module. Not present in CISA KEV; no active in-the-wild exploitation confirmed as of disclosure.

- **Published:** 2026-07-22T00:00:00Z
- **Last reviewed:** 2026-07-22T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1638
- **ID:** TL-2026-1638
- **Severity:** CRITICAL (CVSS 9.1)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 18 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-60167, CVE-2026-60168, CVE-2026-60169, CVE-2026-60170

## Description

Oracle Hospitality Simphony is a widely deployed cloud-based point-of-sale (POS) platform used across the hospitality and food-service industry to process guest transactions, manage printing/kitchen-display workflows, and support self-service ordering via the Simphony Kiosk application. On 2026-07-21, Horizon3.ai attack researcher Jimi Sebree published technical analysis of four vulnerabilities affecting Simphony versions 19.8 through 19.8.5, 19.9 through 19.9.3, and 19.10 (earlier, unsupported release lines may also be affected), coordinated with Oracle's July 2026 Critical Patch Update (cpujul2026), a mega-CPU that addressed 1,235 CVEs across 32 Oracle product families/1,449 patches in total.

CVE-2026-60167 is a UNC path coercion vulnerability in the EGateway Printing Handler. Because the handler insufficiently validates user-controlled input used to build printer/network paths, an unauthenticated network attacker can supply a crafted UNC path (e.g. pointing at an attacker-controlled SMB listener) and force the Simphony host to initiate an outbound SMB connection to it. Windows automatically attempts NTLM authentication during that outbound connection, disclosing the host's NTLM authentication material (NetNTLM hash) to the attacker. Horizon3.ai's write-up explicitly frames this as an SMB-relay-enabling primitive: the captured hash can be cracked offline to recover the plaintext service-account password, or relayed in real time (NTLM relay / SMB relay) against other hosts that accept the same credential, potentially yielding remote code execution or further lateral movement without ever needing the original password. CVSS 3.1 base score 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) — confidentiality-only impact reflecting the credential-disclosure primitive.

CVE-2026-60168 and CVE-2026-60169 are two related but independently tracked arbitrary file write vulnerabilities in the same EGateway Printing Handler, both stemming from insufficient validation of attacker-supplied paths/content before file operations are performed on the host filesystem. CVE-2026-60168 (CVSS 3.1 9.1 CRITICAL, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H) is an easily exploitable (AC:L) unauthenticated HTTP-reachable flaw enabling unauthorized creation, deletion, or modification of critical data and denial of service (host crash). CVE-2026-60169 (CVSS 3.1 8.1 HIGH, AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H) is a harder-to-exploit (AC:H) variant of the same underlying weakness class but yields complete compromise of confidentiality, integrity, and availability when successful. Chained together, an attacker can write attacker-controlled files (e.g. a web shell or scheduled task payload) to the Simphony host, establishing persistence and staging code execution — Horizon3.ai's advisory groups both file-write CVEs under 'persistent code execution preparation' as the shared impact category.

CVE-2026-60170 is an authentication bypass in the Simphony Kiosk self-service ordering application (CVSS 3.1 7.5 HIGH, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). Because the Kiosk application insufficiently validates a user-controlled input used in its authentication flow, an unauthenticated network attacker can bypass login and reach the Kiosk administrator console — a management interface not intended to be exposed to unauthenticated users. Horizon3.ai researchers demonstrated that administrator-console access can be leveraged to execute arbitrary code, establish persistence (including via unauthorized admin account creation, which Horizon3.ai flags as a specific post-exploitation indicator), access locally stored data (which may include payment/transaction artifacts depending on deployment), and pivot toward other assets on the same network segment as the kiosk terminal (common in retail/restaurant back-of-house LANs shared with POS controllers and payment infrastructure).

All four vulnerabilities are unauthenticated, network-exploitable (AV:N), require no user interaction (UI:N), require no privileges (PR:N), and were disclosed with coordinated Oracle patches in the July 2026 CPU. Horizon3.ai's public technical write-up withheld a full weaponized proof-of-concept but described attack mechanics in sufficient detail (UNC coercion pattern, file-write primitive, kiosk auth-bypass class, HTTP-endpoint reachability) that a motivated attacker could plausibly reconstruct working exploits, particularly given Simphony's prevalence in hospitality environments where POS/kiosk terminals are frequently internet- or vendor-network-adjacent. Horizon3.ai's mitigation guidance explicitly recommends Extended Protection for Authentication (EPA) alongside SMB signing, and monitoring for unauthorized SMB connections, unexpected file modifications, and unauthorized admin account creation. As of 2026-07-22 the four CVEs are not present in the CISA Known Exploited Vulnerabilities catalog (1,653 entries as of that date), consistent with the 'no active exploitation confirmed' assessment; Horizon3.ai released a single NodeZero Rapid Response test module allowing customers to both validate exploitability pre-patch and verify remediation post-patch without causing system damage.

## MITRE ATT&CK

- T1595.002 Vulnerability Scanning
- T1588.005 Exploits
- T1587.001 Malware
- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1505.003 Web Shell
- T1136.001 Local Account
- T1068 Exploitation for Privilege Escalation
- T1550.002 Pass the Hash
- T1070.004 File Deletion
- T1187 Forced Authentication
- T1557.001 Name Resolution Poisoning and SMB Relay
- T1110.002 Password Cracking
- T1046 Network Service Discovery
- T1210 Exploitation of Remote Services
- T1005 Data from Local System
- T1071 Application Layer Protocol
- T1499 Endpoint Denial of Service
- T1485 Data Destruction

## Sources

- [Oracle Hospitality Simphony Vulnerabilities](https://horizon3.ai/attack-research/vulnerabilities/oracle-hospitality-simphony-vulnerabilities/)
- [Oracle Critical Patch Update Advisory - July 2026](https://www.oracle.com/security-alerts/cpujul2026.html)
- [Text Form of Oracle CPU July 2026 Risk Matrices](https://www.oracle.com/security-alerts/cpujul2026verbose.html)
- [NVD - CVE-2026-60167](https://nvd.nist.gov/vuln/detail/CVE-2026-60167)
- [NVD - CVE-2026-60168](https://nvd.nist.gov/vuln/detail/CVE-2026-60168)
- [NVD - CVE-2026-60169](https://nvd.nist.gov/vuln/detail/CVE-2026-60169)
- [NVD - CVE-2026-60170](https://nvd.nist.gov/vuln/detail/CVE-2026-60170)
- [Horizon3.ai NodeZero Rapid Response](https://horizon3.ai/nodezero/rapid-response/)
- [Rapid Response - HORIZON3 Documentation](https://docs.horizon3.ai/rapid_response/)
- [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json)
- [Oracle July 2026 Critical Patch Update Addresses 1235 CVEs - Threat Radar](https://radar.offseq.com/threat/oracle-july-2026-critical-patch-update-addresses-1235-cves-d66048a2fadaf3f4)
- [Map of CVE to Advisory/Alert - Oracle](https://www.oracle.com/security-alerts/public-vuln-to-advisory-mapping.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1638
