Description
Vulnerability in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security). The supported version that is affected is 26.1.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where GoldenGate Stream Analytics executes to compromise GoldenGate Stream Analytics. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of GoldenGate Stream Analytics. CVSS 3.1 Base Score 3.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).
Published: 2026-07-21
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a CWE‑400 resource exhaustion or input validation issue in the Security component of Oracle GoldenGate Stream Analytics 26.1.0.0.0. A low‑privileged user with host login privileges can exploit the flaw to compromise the application, causing a partial denial of service that affects the availability of the software while leaving confidentiality and integrity intact.

Affected Systems

Oracle GoldenGate Stream Analytics version 26.1.0.0.0, provided by Oracle Corporation, is the only product explicitly listed by the CNA as vulnerable. No other versions or variants were identified as affected.

Risk and Exploitability

The CVSS base score of 3.3 indicates low severity, with an availability‑only impact (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L). The EPSS score is less than 1 %, showing a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local low‑privilege access to the host; a remote attacker would need an additional foothold. The partial denial of service could disrupt critical data streams but does not expose or alter data confidentiality or integrity.

Generated by OpenCVE AI on August 3, 2026 at 00:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle‑provided security update for Oracle GoldenGate Stream Analytics 26.1.0.0.0 as soon as it becomes available.
  • Restrict local access to the GoldenGate host to trusted administrators and remove or disable unused accounts.
  • Enable monitoring and logging of service availability to detect and mitigate repeated denial‑of‑service attempts.

Generated by OpenCVE AI on August 3, 2026 at 00:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Local Logon Exploit Enables Partial Denial of Service in Oracle GoldenGate Stream Analytics

Tue, 28 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Local Partial Denial of Service in Oracle GoldenGate Stream Analytics 26.1

Fri, 24 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Local Partial Denial of Service in Oracle GoldenGate Stream Analytics 26.1

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security). The supported version that is affected is 26.1.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where GoldenGate Stream Analytics executes to compromise GoldenGate Stream Analytics. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of GoldenGate Stream Analytics. CVSS 3.1 Base Score 3.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).
First Time appeared Oracle
Oracle goldengate Stream Analytics
CPEs cpe:2.3:a:oracle:goldengate_stream_analytics:26.1.0.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle goldengate Stream Analytics
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Oracle Goldengate Stream Analytics
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:25:25.897Z

Reserved: 2026-05-18T15:55:10.317Z

Link: CVE-2026-47022

cve-icon Vulnrichment

Updated: 2026-07-23T15:23:14.012Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T00:15:17Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption