#VU121723 Improper input validation in Oracle Hospitality OPERA 5 Property Services - CVE-2026-21967
Published: January 20, 2026
Oracle Hospitality OPERA 5 Property Services
Oracle
Description
The vulnerability allows a remote non-authenticated attacker to read, manipulate or delete data.
The vulnerability exists due to improper input validation within the Opera Servlet component in Oracle Hospitality OPERA 5 Property Services. A remote non-authenticated attacker can exploit this vulnerability to read, manipulate or delete data.