A critical vulnerability, CVE-2026-4408, has been published with a CVSS score of 9.0, affecting Samba file servers and classic domain controllers that use the "check password script" feature. The…
CVE-2026-34311 (CVSS 9.8) — Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera). Supported versions that are affected are 5.6.19.24, 5.6.22, 5.6.25.19,
CVE. Sourced from nvd, summarised by Matproof.
AI Analysis
What changed and what to do.
A critical vulnerability has been published under CVE-2026-34311, affecting Oracle Hospitality OPERA 5 Property Services, specifically versions 5.6.19.24, 5.6.22, and 5.6.25.19. The vulnerability carries a CVSS score of 9.8, indicating it is critical and remotely exploitable without authentication. This means an attacker could potentially gain full control over the affected system without needing any user credentials or interaction.
Organizations most affected are those in the hospitality sector, including hotels, resorts, and property management companies that rely on Oracle OPERA 5 for reservations, billing, and guest data management. Given the high severity and the nature of the software, this vulnerability poses a direct risk to personal data processing, which may trigger obligations under GDPR and other EU data protection regulations if guest information is compromised.
Compliance teams should immediately verify whether their organization uses any of the affected versions and prioritize patching as soon as Oracle releases a security update. In the interim, network segmentation and strict access controls should be applied to limit exposure. Additionally, teams should assess whether this vulnerability requires notification to data protection authorities or affected data subjects under applicable breach notification rules.
This summary is AI-generated for orientation purposes. For regulatory action, always consult the original source linked above.
More CVE updates
Latest in CVE.
A critical vulnerability has been published under CVE-2026-24444, affecting SDMC NE6037 cable modem routers running firmware versions 7.1.6.0.25 and 7.1.6.1.9_B9. The issue involves a hardcoded…
A critical vulnerability has been published under CVE-2026-46775, affecting Oracle REST Data Services in versions 24.2.0 through 26.1.0. The flaw, rated 9.9 on the CVSS scale, is easily exploitable…
A critical vulnerability has been published under CVE-2026-46817, affecting the Oracle Payments component of Oracle E-Business Suite, specifically versions 12.2.3 through 12.2.15. The flaw, rated 9.8…
Map this to your controls
Connect regulatory changes to your compliance work.
Matproof maps every regulator update directly to your controls and surfaces the ones that affect your organisation — across 21 frameworks.