CVE-2026-21953
LOW
3.3
CVSS 3.1
Metadata
Severity & Metrics
3.3
LOW CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
SSVC — CISA Coordinator
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Oracle Corporation | Oracle Retail Xstore Point of Service | — | 21.0.3 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| — | cna | Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Retail Xstore Point of Service executes to compromise Oracle Retail Xstore Point of Service. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Retail Xstore Point of Service accessible data. |
| CWE-284 | adp | CWE-284 Improper Access Control |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 3.3 | LOW | 3.1 | cna | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
References (1)
- Oracle Advisory https://www.oracle.com/security-alerts/cpujul2026.html