Description
Vulnerability in Oracle GoldenGate (component: Service Manager). Supported versions that are affected are 19.1.0.0.0-19.29.0.0, 21.3-21.21 and 23.4-23.26.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle GoldenGate Service Manager contains an Improper Access Control flaw (CWE‑284) that permits a low‑privileged adversary with network access over HTTP to compromise the system. Once exploited, an attacker can gain full control of the GoldenGate deployment, leading to complete takeover of the application. The vulnerability is classified as a Remote Code Execution issue, affecting Confidentiality, Integrity, and Availability.

Affected Systems

Oracle GoldenGate versions 19.1.0.0.0 through 19.29.0.0, 21.3 through 21.21, and 23.4 through 23.26.1.0.0 are affected. Users of these releases must confirm their instances fall within these ranges.

Risk and Exploitability

The CVSS base score of 8.8 underscores a high severity threat, with potential for full system compromise. The EPSS score of less than 1% indicates that, as of now, exploitation is not widely observed, and the vulnerability is not catalogued in CISA’s KEV list. Despite low current exploitation probability, the vector is network‑based and requires only an attacker able to reach the HTTP endpoint, making the risk significant for exposed deployments.

Generated by OpenCVE AI on August 2, 2026 at 23:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle GoldenGate patch that addresses the Service Manager issue
  • Restrict access to the Service Manager HTTP interface to trusted IP ranges or internal networks, blocking all other traffic
  • Monitor Service Manager logs and audit trails for anomalous activity and configure alerting on suspicious authentication attempts

Generated by OpenCVE AI on August 2, 2026 at 23:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Title Exploitable Vulnerability in Oracle GoldenGate Service Manager Enabling Takeover via HTTP

Sun, 26 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Exploitable Vulnerability in Oracle GoldenGate Service Manager Enabling Takeover via HTTP

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in Oracle GoldenGate (component: Service Manager). Supported versions that are affected are 19.1.0.0.0-19.29.0.0, 21.3-21.21 and 23.4-23.26.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle goldengate
CPEs cpe:2.3:a:oracle:goldengate:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle goldengate
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Goldengate
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:16:24.563Z

Reserved: 2026-07-08T15:51:40.515Z

Link: CVE-2026-60157

cve-icon Vulnrichment

Updated: 2026-07-23T15:16:14.116Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T23:45:03Z

Weaknesses