THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-21954 (MEDIUM 4.3) — Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). The supported version that is affected is 21.0.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to comprom

[NVD] CVE-2026-21954 (MEDIUM 4.3) — Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). The supported version that is affected is 21.0.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to comprom

mednvdPublished 2026-07-21

CVE-2026-21954 CVSS: 4.3 MEDIUM Published: 2026-07-21T22:17:00.763

Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). The supported version that is affected is 21.0.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service. Successf

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-21954